Logo
vulnerabilityCVE-2021-41072
Name
CVE-2021-41072
Source
NVD ( link)Debian ( link)
Description
squashfs_opendir in unsquash-2.c in Squashfs-Tools 4.5 allows Directory Traversal, a different vulnerability than CVE-2021-40153. A squashfs filesystem that has been crafted to include a symbolic link and then contents under the same filename in a filesystem can cause unsquashfs to first create the symbolic link pointing outside the expected directory, and then the subsequent write operation will cause the unsquashfs process to write through the symbolic link elsewhere in the filesystem.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
squashfs-tools
Patched

Vulnerability Ratings#


8.1
CVSSv31
5.8
CVSSv2

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
4.6.1
Not Affected
buildroot
master
4.7.5
Not Affected
yocto
master
4.7.5
Not Affected
yocto
scarthgap
4.6.1
Not Affected

Resolved with patches#


squashfs-tools (yocto:kirkstone)

#
Title
Author
Resolve
1
Unsquashfs: additional write outside destination directory
Phillip Lougher <phillip@squashfs.org.uk>
CVE-2021-41072