CVE-2012-4024
published 2012-07-19CVE-2012-4024: Stack-based buffer overflow in the get_component function in unsquashfs.c in unsquashfs in Squashfs 4.2 and earlier allows remote attackers to execute…
PriorityP430medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
4.05%
89.5th percentile
Stack-based buffer overflow in the get_component function in unsquashfs.c in unsquashfs in Squashfs 4.2 and earlier allows remote attackers to execute arbitrary code via a crafted list file (aka a crafted file for the -ef option). NOTE: probably in most cases, the list file is a trusted file constructed by the program's user; however, there are some realistic situations in which a list file would be obtained from an untrusted remote source.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | squashfs-tools | < squashfs-tools 1:4.2+20121212-1 (bookworm) | squashfs-tools 1:4.2+20121212-1 (bookworm) |
| squashfs-tools_project | squashfs-tools | >= 0 < 1:4.2+20121212-1 | 1:4.2+20121212-1 |
| squashfs-tools_project | squashfs-tools | >= 0 < 1:4.2+20121212-1 | 1:4.2+20121212-1 |
| squashfs-tools_project | squashfs-tools | >= 0 < 1:4.2+20121212-1 | 1:4.2+20121212-1 |
| squashfs-tools_project | squashfs-tools | >= 0 < 1:4.2+20121212-1 | 1:4.2+20121212-1 |
| squashfs_project | squashfs | <= 4.2 | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_debian6.8LOW
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
squashfs-tools: remote arbitrary code execution via crafted list file
vendor_redhat·2012-07-18·CVSS 6.8
CVE-2012-4024 [MEDIUM] squashfs-tools: remote arbitrary code execution via crafted list file
squashfs-tools: remote arbitrary code execution via crafted list file
Stack-based buffer overflow in the get_component function in unsquashfs.c in unsquashfs in Squashfs 4.2 and earlier allows remote attackers to execute arbitrary code via a crafted list file (aka a crafted file for the -ef option). NOTE: probably in most cases, the list file is a trusted file constructed by the program's user; however, there are some realistic situations in which a list file would be obtained from an untrusted remote source.
Package: squashfs-tools (Red Hat Enterprise Linux 5) - Not affected
Package: squashfs-tools (Red Hat Enterprise Linux 6) - Will not fix
Debian
CVE-2012-4024: squashfs-tools - Stack-based buffer overflow in the get_component function in unsquashfs.c in uns...
vendor_debian·2012·CVSS 6.8
CVE-2012-4024 [MEDIUM] CVE-2012-4024: squashfs-tools - Stack-based buffer overflow in the get_component function in unsquashfs.c in uns...
Stack-based buffer overflow in the get_component function in unsquashfs.c in unsquashfs in Squashfs 4.2 and earlier allows remote attackers to execute arbitrary code via a crafted list file (aka a crafted file for the -ef option). NOTE: probably in most cases, the list file is a trusted file constructed by the program's user; however, there are some realistic situations in which a list file would be obtained from an untrusted remote source.
Scope: local
bookworm: resolved (fixed in 1:4.2+20121212-1)
bullseye: resolved (fixed in 1:4.2+20121212-1)
forky: resolved (fixed in 1:4.2+20121212-1)
sid: resolved (fixed in 1:4.2+20121212-1)
trixie: resolved (fixed in 1:4.2+20121212-1)
GHSA
GHSA-r5cx-4556-w7x7: Stack-based buffer overflow in the get_component function in unsquashfs
ghsa_unreviewed·2022-05-13
CVE-2012-4024 [MEDIUM] CWE-787 GHSA-r5cx-4556-w7x7: Stack-based buffer overflow in the get_component function in unsquashfs
Stack-based buffer overflow in the get_component function in unsquashfs.c in unsquashfs in Squashfs 4.2 and earlier allows remote attackers to execute arbitrary code via a crafted list file (aka a crafted file for the -ef option). NOTE: probably in most cases, the list file is a trusted file constructed by the program's user; however, there are some realistic situations in which a list file would be obtained from an untrusted remote source.
OSV
CVE-2012-4024: Stack-based buffer overflow in the get_component function in unsquashfs
osv·2012-07-19·CVSS 6.8
CVE-2012-4024 [MEDIUM] CVE-2012-4024: Stack-based buffer overflow in the get_component function in unsquashfs
Stack-based buffer overflow in the get_component function in unsquashfs.c in unsquashfs in Squashfs 4.2 and earlier allows remote attackers to execute arbitrary code via a crafted list file (aka a crafted file for the -ef option). NOTE: probably in most cases, the list file is a trusted file constructed by the program's user; however, there are some realistic situations in which a list file would be obtained from an untrusted remote source.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-4024 CVE-2012-4025 squashfs-tools various flaws [fedora-all]
bugzilla·2012-08-10·CVSS 6.8
CVE-2012-4024 [MEDIUM] CVE-2012-4024 CVE-2012-4025 squashfs-tools various flaws [fedora-all]
CVE-2012-4024 CVE-2012-4025 squashfs-tools various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=
Bugzilla
CVE-2012-4024 squashfs-tools: remote arbitrary code execution via crafted list file
bugzilla·2012-07-23·CVSS 6.8
CVE-2012-4024 [MEDIUM] CVE-2012-4024 squashfs-tools: remote arbitrary code execution via crafted list file
CVE-2012-4024 squashfs-tools: remote arbitrary code execution via crafted list file
Common Vulnerabilities and Exposures assigned an identifier CVE-2012-4024 to
the following vulnerability:
Name: CVE-2012-4024
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4024
Assigned: 20120716
Reference: http://sourceforge.net/mailarchive/forum.php?thread_name=CAAoG81HL9oP8roPLLhftTSXTzSD%2BZcR66PRkVU%3Df76W3Mjde_w%40mail.gmail.com&forum_name=squashfs-devel
Reference: http://www.osvdb.org/83898
Stack-based buffer overflow in the get_component function in
unsquashfs.c in unsquashfs in Squashfs 4.2 and earlier allows remote
attackers to execute arbitrary code via a crafted list file (aka a
crafted file for the -ef option). NOTE: probably in most cases, the
list file is a trusted file const
http://sourceforge.net/mailarchive/forum.php?thread_name=CAAoG81HL9oP8roPLLhftTSXTzSD%2BZcR66PRkVU%3Df76W3Mjde_w%40mail.gmail.com&forum_name=squashfs-develhttp://www.mandriva.com/security/advisories?name=MDVSA-2013:128http://www.openwall.com/lists/oss-security/2012/07/19/6http://www.osvdb.org/83898http://www.securityfocus.com/bid/54610https://exchange.xforce.ibmcloud.com/vulnerabilities/77106https://security.gentoo.org/glsa/201612-40https://wiki.mageia.org/en/Support/Advisories/MGASA-2013-0001http://sourceforge.net/mailarchive/forum.php?thread_name=CAAoG81HL9oP8roPLLhftTSXTzSD%2BZcR66PRkVU%3Df76W3Mjde_w%40mail.gmail.com&forum_name=squashfs-develhttp://www.mandriva.com/security/advisories?name=MDVSA-2013:128http://www.openwall.com/lists/oss-security/2012/07/19/6http://www.osvdb.org/83898http://www.securityfocus.com/bid/54610https://exchange.xforce.ibmcloud.com/vulnerabilities/77106https://security.gentoo.org/glsa/201612-40https://wiki.mageia.org/en/Support/Advisories/MGASA-2013-0001
2012-07-19
Published