5.8 Medium
CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:N/AC:M/Au:N/C:N/I:P/A:P
8.1 High
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
0.012 Low
EPSS
Percentile
85.3%
squashfs_opendir in unsquash-1.c in Squashfs-Tools 4.5 stores the filename
in the directory entry; this is then used by unsquashfs to create the new
file during the unsquash. The filename is not validated for traversal
outside of the destination directory, and thus allows writing to locations
outside of the destination.
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
ubuntu | 18.04 | noarch | squashfs-tools | < 1:4.3-6ubuntu0.18.04.3 | UNKNOWN |
ubuntu | 20.04 | noarch | squashfs-tools | < 1:4.4-1ubuntu0.1 | UNKNOWN |
ubuntu | 21.04 | noarch | squashfs-tools | < 1:4.4-2ubuntu0.1 | UNKNOWN |
ubuntu | 21.10 | noarch | squashfs-tools | < 1:4.4-2ubuntu1 | UNKNOWN |
ubuntu | 22.04 | noarch | squashfs-tools | < 1:4.4-2ubuntu1 | UNKNOWN |
ubuntu | 16.04 | noarch | squashfs-tools | < 1:4.3-3ubuntu2.16.04.3+esm1 | UNKNOWN |
bugs.launchpad.net/ubuntu/+source/squashfs-tools/+bug/1941790
github.com/plougher/squashfs-tools/commit/79b5a555058eef4e1e7ff220c344d39f8cd09646
github.com/plougher/squashfs-tools/commit/79b5a555058eef4e1e7ff220c344d39f8cd09646 (4.5)
github.com/plougher/squashfs-tools/issues/72
launchpad.net/bugs/cve/CVE-2021-40153
nvd.nist.gov/vuln/detail/CVE-2021-40153
security-tracker.debian.org/tracker/CVE-2021-40153
ubuntu.com/security/notices/USN-5057-1
ubuntu.com/security/notices/USN-5078-2
www.cve.org/CVERecord?id=CVE-2021-40153
5.8 Medium
CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:N/AC:M/Au:N/C:N/I:P/A:P
8.1 High
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
0.012 Low
EPSS
Percentile
85.3%