CVE-2011-5325Path Traversal in Busybox

Severity
9.8CRITICALNVD
NVD7.5OSV7.5
EPSS
3.8%
top 11.93%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 7
Latest updateMay 13

Description

Directory traversal vulnerability in the BusyBox implementation of tar before 1.22.0 v5 allows remote attackers to point to files outside the current working directory via a symlink.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages5 packages

debiandebian/busybox< busybox 1:1.27.2-1 (bookworm)
Debianbusybox/busybox< 1:1.27.2-1+3
Ubuntubusybox/busybox< 1:1.21.0-1ubuntu1.4+2
NVDbusybox/busybox1.21.1

Also affects: Debian Linux 8.0, 9.0, Ubuntu Linux 14.04, 16.04, 18.04, 18.10

🔴Vulnerability Details

4
GHSA
GHSA-28cm-w7c9-p27f: Directory traversal vulnerability in the BusyBox implementation of tar before 12022-05-13
GHSA
GHSA-5f63-p3w5-jphc: NUUO NVRmini2 through 32022-01-15
OSV
busybox vulnerabilities2019-04-03
OSV
CVE-2011-5325: Directory traversal vulnerability in the BusyBox implementation of tar before 12017-08-07

📋Vendor Advisories

3
Ubuntu
BusyBox vulnerabilities2019-04-03
Red Hat
busybox: Path traversal via crafted tar file containing symlink2015-10-20
Debian
CVE-2011-5325: busybox - Directory traversal vulnerability in the BusyBox implementation of tar before 1....2011

💬Community

2
Bugzilla
CVE-2011-5325 busybox: Path traversal via crafted tar file containing symlink [fedora-all]2015-10-22
Bugzilla
CVE-2011-5325 busybox: Path traversal via crafted tar file containing symlink2015-10-22