cbcvebase.
CVE-2021-23177
published 2022-08-23

CVE-2021-23177: An improper link resolution flaw while extracting an archive can lead to changing the access control list (ACL) of the target of the link. An attacker may…

PriorityP337high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.37%
29.3th percentile
An improper link resolution flaw while extracting an archive can lead to changing the access control list (ACL) of the target of the link. An attacker may provide a malicious archive to a victim user, who would trigger this flaw when trying to extract the archive. A local attacker may use this flaw to change the ACL of a file on the system and gain more privileges.

Affected

19 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianlibarchive< libarchive 3.5.2-1 (bookworm)libarchive 3.5.2-1 (bookworm)
fedoraprojectfedora
libarchivelibarchive< 3.5.23.5.2
libarchivelibarchive
libarchivelibarchive>= 0 < 3.4.3-2+deb11u13.4.3-2+deb11u1
libarchivelibarchive>= 0 < 3.5.2-13.5.2-1
libarchivelibarchive>= 0 < 3.5.2-13.5.2-1
libarchivelibarchive>= 0 < 3.5.2-13.5.2-1
libarchivelibarchive>= 0 < 3.4.0-2ubuntu1.13.4.0-2ubuntu1.1
redhatenterprise_linux
redhatenterprise_linux_eus
redhatenterprise_linux_for_ibm_z_systems
redhatenterprise_linux_for_ibm_z_systems_eus
redhatenterprise_linux_for_power_little_endian
redhatenterprise_linux_for_power_little_endian_eus
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_for_power_little_endian_update_services_for_sap_solution
redhatenterprise_linux_server_tus

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.