CVE-2021-41072
published 2021-09-14CVE-2021-41072: squashfs_opendir in unsquash-2.c in Squashfs-Tools 4.5 allows Directory Traversal, a different vulnerability than CVE-2021-40153. A squashfs filesystem that…
PriorityP341high8.1CVSS 3.1
AVNACLPRNUIRSUCNIHAH
EPSS
2.30%
81.5th percentile
squashfs_opendir in unsquash-2.c in Squashfs-Tools 4.5 allows Directory Traversal, a different vulnerability than CVE-2021-40153. A squashfs filesystem that has been crafted to include a symbolic link and then contents under the same filename in a filesystem can cause unsquashfs to first create the symbolic link pointing outside the expected directory, and then the subsequent write operation will cause the unsquashfs process to write through the symbolic link elsewhere in the filesystem.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | squashfs-tools | < squashfs-tools 1:4.5-3 (bookworm) | squashfs-tools 1:4.5-3 (bookworm) |
| msrc | cbl2_squashfs-tools_4.5.1-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| squashfs-tools_project | squashfs-tools | — | — |
| squashfs-tools_project | squashfs-tools | >= 0 < 1:4.4-2+deb11u2 | 1:4.4-2+deb11u2 |
| squashfs-tools_project | squashfs-tools | >= 0 < 1:4.5-3 | 1:4.5-3 |
| squashfs-tools_project | squashfs-tools | >= 0 < 1:4.5-3 | 1:4.5-3 |
| squashfs-tools_project | squashfs-tools | >= 0 < 1:4.5-3 | 1:4.5-3 |
| squashfs-tools_project | squashfs-tools | >= 0 < 1:4.3-3ubuntu2.16.04.3+esm1 | 1:4.3-3ubuntu2.16.04.3+esm1 |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:P
osv8.1HIGH
vendor_debian8.1HIGH
vendor_msrc8.1HIGH
vendor_redhat8.1HIGH
vendor_ubuntu8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Squashfs-Tools vulnerability
vendor_ubuntu·2021-10-13
CVE-2021-41072 Squashfs-Tools vulnerability
Title: Squashfs-Tools vulnerability
Summary: Squashfs-Tools could be made to overwrite files.
USN-5078-1 fixed a vulnerability in Squashfs-Tools. That update was
incomplete and could still result in Squashfs-Tools mishandling certain
malformed SQUASHFS files. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Richard Weinberger discovered that Squashfs-Tools mishandled certain
malformed SQUASHFS files. An attacker could use this vulnerability to
write arbitrary files to the filesystem.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Squashfs-Tools vulnerabilities
vendor_ubuntu·2021-09-15·CVSS 8.1
CVE-2021-40153 [HIGH] Squashfs-Tools vulnerabilities
Title: Squashfs-Tools vulnerabilities
Summary: Squashfs-Tools could be made to overwrite files.
USN-5078-1 fixed several vulnerabilities in Squashfs-Tools.
This update provides the corresponding update for Ubuntu 16.04 ESM.
Original advisory details:
Etienne Stalmans discovered that Squashfs-Tools mishandled certain
malformed SQUASHFS files. An attacker could use this vulnerability
to write arbitrary files to the filesystem. (CVE-2021-40153)
Richard Weinberger discovered that Squashfs-Tools mishandled certain
malformed SQUASHFS files. An attacker could use this vulnerability to
write arbitrary files to the filesystem. (CVE-2021-41072)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Squashfs-Tools vulnerability
vendor_ubuntu·2021-09-15
CVE-2021-41072 Squashfs-Tools vulnerability
Title: Squashfs-Tools vulnerability
Summary: Squashfs-Tools could be made to overwrite files.
Richard Weinberger discovered that Squashfs-Tools mishandled certain
malformed SQUASHFS files. An attacker could use this vulnerability to
write arbitrary files to the filesystem.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
squashfs-tools: possible Directory Traversal via symbolic link
vendor_redhat·2021-09-14·CVSS 8.1
CVE-2021-41072 [HIGH] CWE-59 squashfs-tools: possible Directory Traversal via symbolic link
squashfs-tools: possible Directory Traversal via symbolic link
squashfs_opendir in unsquash-2.c in Squashfs-Tools 4.5 allows Directory Traversal, a different vulnerability than CVE-2021-40153. A squashfs filesystem that has been crafted to include a symbolic link and then contents under the same filename in a filesystem can cause unsquashfs to first create the symbolic link pointing outside the expected directory, and then the subsequent write operation will cause the unsquashfs process to write through the symbolic link elsewhere in the filesystem.
A directory traversal flaw was found in squashfs-tools. During extraction, a file can escape the destination directory by using a symbolic link, and a regular file with an identical name. This flaw allows a specially crafted squashfs archive
Microsoft
squashfs_opendir in unsquash-2.c in Squashfs-Tools 4.5 allows Directory Traversal a different vulnerability than CVE-2021-40153. A squashfs filesystem that has been crafted to include a symbolic link
vendor_msrc·2021-09-14·CVSS 8.1
CVE-2021-41072 [HIGH] CWE-22 squashfs_opendir in unsquash-2.c in Squashfs-Tools 4.5 allows Directory Traversal a different vulnerability than CVE-2021-40153. A squashfs filesystem that has been crafted to include a symbolic link
squashfs_opendir in unsquash-2.c in Squashfs-Tools 4.5 allows Directory Traversal a different vulnerability than CVE-2021-40153. A squashfs filesystem that has been crafted to include a symbolic link and then contents under the same filename in a filesystem can cause unsquashfs to first create the symbolic link pointing outside the expected directory and then the subsequent write operation will cause the unsquashfs process to write through the symbolic link elsewhere in the filesystem.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure v
Debian
CVE-2021-41072: squashfs-tools - squashfs_opendir in unsquash-2.c in Squashfs-Tools 4.5 allows Directory Traversa...
vendor_debian·2021·CVSS 8.1
CVE-2021-41072 [HIGH] CVE-2021-41072: squashfs-tools - squashfs_opendir in unsquash-2.c in Squashfs-Tools 4.5 allows Directory Traversa...
squashfs_opendir in unsquash-2.c in Squashfs-Tools 4.5 allows Directory Traversal, a different vulnerability than CVE-2021-40153. A squashfs filesystem that has been crafted to include a symbolic link and then contents under the same filename in a filesystem can cause unsquashfs to first create the symbolic link pointing outside the expected directory, and then the subsequent write operation will cause the unsquashfs process to write through the symbolic link elsewhere in the filesystem.
Scope: local
bookworm: resolved (fixed in 1:4.5-3)
bullseye: resolved (fixed in 1:4.4-2+deb11u2)
forky: resolved (fixed in 1:4.5-3)
sid: resolved (fixed in 1:4.5-3)
trixie: resolved (fixed in 1:4.5-3)
GHSA
GHSA-f6m6-9fjw-69qm: squashfs_opendir in unsquash-2
ghsa_unreviewed·2022-05-24·CVSS 8.1
CVE-2021-41072 [HIGH] CWE-22 GHSA-f6m6-9fjw-69qm: squashfs_opendir in unsquash-2
squashfs_opendir in unsquash-2.c in Squashfs-Tools 4.5 allows Directory Traversal, a different vulnerability than CVE-2021-40153. A squashfs filesystem that has been crafted to include a symbolic link and then contents under the same filename in a filesystem can cause unsquashfs to first create the symbolic link pointing outside the expected directory, and then the subsequent write operation will cause the unsquashfs process to write through the symbolic link elsewhere in the filesystem.
OSV
squashfs-tools vulnerabilities
osv·2021-09-15·CVSS 8.1
CVE-2021-40153 [HIGH] squashfs-tools vulnerabilities
squashfs-tools vulnerabilities
USN-5078-1 fixed several vulnerabilities in Squashfs-Tools.
This update provides the corresponding update for Ubuntu 16.04 ESM.
Original advisory details:
Etienne Stalmans discovered that Squashfs-Tools mishandled certain
malformed SQUASHFS files. An attacker could use this vulnerability
to write arbitrary files to the filesystem. (CVE-2021-40153)
Richard Weinberger discovered that Squashfs-Tools mishandled certain
malformed SQUASHFS files. An attacker could use this vulnerability to
write arbitrary files to the filesystem. (CVE-2021-41072)
OSV
CVE-2021-41072: squashfs_opendir in unsquash-2
osv·2021-09-14·CVSS 8.1
CVE-2021-41072 [HIGH] CVE-2021-41072: squashfs_opendir in unsquash-2
squashfs_opendir in unsquash-2.c in Squashfs-Tools 4.5 allows Directory Traversal, a different vulnerability than CVE-2021-40153. A squashfs filesystem that has been crafted to include a symbolic link and then contents under the same filename in a filesystem can cause unsquashfs to first create the symbolic link pointing outside the expected directory, and then the subsequent write operation will cause the unsquashfs process to write through the symbolic link elsewhere in the filesystem.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/plougher/squashfs-tools/commit/e0485802ec72996c20026da320650d8362f555bdhttps://github.com/plougher/squashfs-tools/issues/72#issuecomment-913833405https://lists.debian.org/debian-lts-announce/2021/10/msg00017.htmlhttps://security.gentoo.org/glsa/202305-29https://www.debian.org/security/2021/dsa-4987https://github.com/plougher/squashfs-tools/commit/e0485802ec72996c20026da320650d8362f555bdhttps://github.com/plougher/squashfs-tools/issues/72#issuecomment-913833405https://lists.debian.org/debian-lts-announce/2021/10/msg00017.htmlhttps://security.gentoo.org/glsa/202305-29https://www.debian.org/security/2021/dsa-4987
2021-09-14
Published