CVE-2021-31566Link Following in Libarchive

CWE-59Link Following8 documents7 sources
Severity
7.8HIGHNVD
EPSS
0.0%
top 88.56%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 23
Latest updateAug 24

Description

An improper link resolution flaw can occur while extracting an archive leading to changing modes, times, access control lists, and flags of a file outside of the archive. An attacker may provide a malicious archive to a victim user, who would trigger this flaw when trying to extract the archive. A local attacker may use this flaw to gain more privileges in a system.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages5 packages

Debianlibarchive/libarchive< 3.4.3-2+deb11u1+3
Ubuntulibarchive/libarchive< 3.4.0-2ubuntu1.1
CVEListV5libarchive/libarchiveFixed in libarchive 3.5.2
NVDsplunk/universal_forwarder8.2.08.2.12+2

Also affects: Debian Linux 10.0, Fedora 35, Enterprise Linux 8.0, 8.6

Patches

🔴Vulnerability Details

4
GHSA
GHSA-mg62-fpgc-6hjj: An improper link resolution flaw can occur while extracting an archive leading to changing modes, times, access control lists, and flags of a file out2022-08-24
CVEList
CVE-2021-31566: An improper link resolution flaw can occur while extracting an archive leading to changing modes, times, access control lists, and flags of a file out2022-08-23
OSV
CVE-2021-31566: An improper link resolution flaw can occur while extracting an archive leading to changing modes, times, access control lists, and flags of a file out2022-08-23
OSV
libarchive vulnerabilities2022-02-17

📋Vendor Advisories

3
Ubuntu
libarchive vulnerabilities2022-02-17
Red Hat
libarchive: symbolic links incorrectly followed when changing modes, times, ACL and flags of a file while extracting an archive2021-08-22
Debian
CVE-2021-31566: libarchive - An improper link resolution flaw can occur while extracting an archive leading t...2021
CVE-2021-31566 — Link Following in Libarchive | cvebase