CVE-2021-41072
squashfs-tools - security update
8.1
HIGH
CVSS 3.1
EPSS 2.1%
描述
squashfs_opendir in unsquash-2.c in Squashfs-Tools 4.5 allows Directory Traversal, a different vulnerability than CVE-2021-40153. A squashfs filesystem that has been crafted to include a symbolic link and then contents under the same filename in a filesystem can cause unsquashfs to first create the symbolic link pointing outside the expected directory, and then the subsequent write operation will cause the unsquashfs process to write through the symbolic link elsewhere in the filesystem.
如何修補 CVE-2021-41072
要修補 CVE-2021-41072,請將受影響套件升級到下列已修補版本。
- —升級至 4.5-r1 或更新版本
- —升級至 1:4.4-2+deb11u2 或更新版本
- —升級至 1:4.3-3+deb9u3 或更新版本
- —升級至 1:4.3-12+deb10u2 或更新版本
CVE-2021-41072 正在被利用嗎?
低 — EPSS 為 2.1%,目前沒有觀察到大規模利用活動。
受影響套件(4)
- from 0, < 4.5-r1
- from 0, < 1:4.4-2+deb11u2
- from 0, < 1:4.3-3+deb9u3
- from 0, < 1:4.3-12+deb10u2
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH8.1 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H |