CVE-2021-23177
published 2022-08-23CVE-2021-23177: An improper link resolution flaw while extracting an archive can lead to changing the access control list (ACL) of the target of the link. An attacker may…
PriorityP337high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.37%
29.3th percentile
An improper link resolution flaw while extracting an archive can lead to changing the access control list (ACL) of the target of the link. An attacker may provide a malicious archive to a victim user, who would trigger this flaw when trying to extract the archive. A local attacker may use this flaw to change the ACL of a file on the system and gain more privileges.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | libarchive | < libarchive 3.5.2-1 (bookworm) | libarchive 3.5.2-1 (bookworm) |
| fedoraproject | fedora | — | — |
| libarchive | libarchive | < 3.5.2 | 3.5.2 |
| libarchive | libarchive | — | — |
| libarchive | libarchive | >= 0 < 3.4.3-2+deb11u1 | 3.4.3-2+deb11u1 |
| libarchive | libarchive | >= 0 < 3.5.2-1 | 3.5.2-1 |
| libarchive | libarchive | >= 0 < 3.5.2-1 | 3.5.2-1 |
| libarchive | libarchive | >= 0 < 3.5.2-1 | 3.5.2-1 |
| libarchive | libarchive | >= 0 < 3.4.0-2ubuntu1.1 | 3.4.0-2ubuntu1.1 |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_for_ibm_z_systems | — | — |
| redhat | enterprise_linux_for_ibm_z_systems_eus | — | — |
| redhat | enterprise_linux_for_power_little_endian | — | — |
| redhat | enterprise_linux_for_power_little_endian_eus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_for_power_little_endian_update_services_for_sap_solution | — | — |
| redhat | enterprise_linux_server_tus | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-fq9q-7wp8-gpr7: An improper link resolution flaw while extracting an archive can lead to changing the access control list (ACL) of the target of the link
ghsa_unreviewed·2022-08-24
CVE-2021-23177 [HIGH] CWE-59 GHSA-fq9q-7wp8-gpr7: An improper link resolution flaw while extracting an archive can lead to changing the access control list (ACL) of the target of the link
An improper link resolution flaw while extracting an archive can lead to changing the access control list (ACL) of the target of the link. An attacker may provide a malicious archive to a victim user, who would trigger this flaw when trying to extract the archive. A local attacker may use this flaw to change the ACL of a file on the system and gain more privileges.
OSV
CVE-2021-23177: An improper link resolution flaw while extracting an archive can lead to changing the access control list (ACL) of the target of the link
osv·2022-08-23·CVSS 7.8
CVE-2021-23177 [HIGH] CVE-2021-23177: An improper link resolution flaw while extracting an archive can lead to changing the access control list (ACL) of the target of the link
An improper link resolution flaw while extracting an archive can lead to changing the access control list (ACL) of the target of the link. An attacker may provide a malicious archive to a victim user, who would trigger this flaw when trying to extract the archive. A local attacker may use this flaw to change the ACL of a file on the system and gain more privileges.
OSV
libarchive vulnerabilities
osv·2022-02-17·CVSS 7.8
CVE-2021-23177 [HIGH] libarchive vulnerabilities
libarchive vulnerabilities
It was discovered that libarchive incorrectly handled symlinks. If a
user or automated system were tricked into processing a specially crafted
archive, an attacker could possibly use this issue to change modes, times,
ACLs, and flags on arbitrary files. (CVE-2021-23177, CVE-2021-31566)
It was discovered that libarchive incorrectly handled certain RAR archives.
If a user or automated system were tricked into processing a specially
crafted RAR archive, an attacker could use this issue to cause libarchive
to crash, resulting in a denial of service, or possibly execute arbitrary
code. (CVE-2021-36976)
Ubuntu
libarchive vulnerabilities
vendor_ubuntu·2022-02-17·CVSS 7.8
CVE-2021-23177 [HIGH] libarchive vulnerabilities
Title: libarchive vulnerabilities
Summary: Several security issues were fixed in libarchive.
It was discovered that libarchive incorrectly handled symlinks. If a
user or automated system were tricked into processing a specially crafted
archive, an attacker could possibly use this issue to change modes, times,
ACLs, and flags on arbitrary files. (CVE-2021-23177, CVE-2021-31566)
It was discovered that libarchive incorrectly handled certain RAR archives.
If a user or automated system were tricked into processing a specially
crafted RAR archive, an attacker could use this issue to cause libarchive
to crash, resulting in a denial of service, or possibly execute arbitrary
code. (CVE-2021-36976)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
libarchive: extracting a symlink with ACLs modifies ACLs of target
vendor_redhat·2021-08-21·CVSS 7.8
CVE-2021-23177 [HIGH] CWE-59 libarchive: extracting a symlink with ACLs modifies ACLs of target
libarchive: extracting a symlink with ACLs modifies ACLs of target
An improper link resolution flaw while extracting an archive can lead to changing the access control list (ACL) of the target of the link. An attacker may provide a malicious archive to a victim user, who would trigger this flaw when trying to extract the archive. A local attacker may use this flaw to change the ACL of a file on the system and gain more privileges.
An improper link resolution flaw while extracting an archive can lead to changing the access control list (ACL) of the target of the link. An attacker may provide a malicious archive to a victim user, who would trigger this flaw when trying to extract the archive. A local attacker may use this flaw to change the ACL of a file on the system and gain more privile
Debian
CVE-2021-23177: libarchive - An improper link resolution flaw while extracting an archive can lead to changin...
vendor_debian·2021·CVSS 7.8
CVE-2021-23177 [HIGH] CVE-2021-23177: libarchive - An improper link resolution flaw while extracting an archive can lead to changin...
An improper link resolution flaw while extracting an archive can lead to changing the access control list (ACL) of the target of the link. An attacker may provide a malicious archive to a victim user, who would trigger this flaw when trying to extract the archive. A local attacker may use this flaw to change the ACL of a file on the system and gain more privileges.
Scope: local
bookworm: resolved (fixed in 3.5.2-1)
bullseye: resolved (fixed in 3.4.3-2+deb11u1)
forky: resolved (fixed in 3.5.2-1)
sid: resolved (fixed in 3.5.2-1)
trixie: resolved (fixed in 3.5.2-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://access.redhat.com/security/cve/CVE-2021-23177https://bugzilla.redhat.com/show_bug.cgi?id=2024245https://github.com/libarchive/libarchive/commit/fba4f123cc456d2b2538f811bb831483bf336badhttps://github.com/libarchive/libarchive/issues/1565https://lists.debian.org/debian-lts-announce/2022/11/msg00030.htmlhttps://access.redhat.com/security/cve/CVE-2021-23177https://bugzilla.redhat.com/show_bug.cgi?id=2024245https://github.com/libarchive/libarchive/commit/fba4f123cc456d2b2538f811bb831483bf336badhttps://github.com/libarchive/libarchive/issues/1565https://lists.debian.org/debian-lts-announce/2022/11/msg00030.html
2022-08-23
Published