Lucene search

K
redhatcveRedhat.comRH:CVE-2021-40153
HistoryAug 27, 2021 - 6:38 p.m.

CVE-2021-40153

2021-08-2718:38:01
redhat.com
access.redhat.com
11

0.012 Low

EPSS

Percentile

85.3%

A flaw was found in Squashfs-tools, where it is vulnerable to attacks similar to zip-slip. During extraction, a file can escape the destination directory either via the ‘…/’ string to access the parent directory or via symlinks. This flaw allows a specially crafted squashfs archive to install or overwrite files outside of the destination directory.