Lucene search

K
ubuntucveUbuntu.comUB:CVE-2024-5187
HistoryJun 06, 2024 - 12:00 a.m.

CVE-2024-5187

2024-06-0600:00:00
ubuntu.com
ubuntu.com
1
cve-2024-5187
onnx framework
file overwrite
path traversal
tar files
remote code execution
system integrity
security checks
unix

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

9

Confidence

High

EPSS

0

Percentile

10.5%

A vulnerability in the download_model_with_test_data function of the
onnx/onnx framework, version 1.16.0, allows for arbitrary file overwrite
due to inadequate prevention of path traversal attacks in malicious tar
files. This vulnerability enables attackers to overwrite any file on the
system, potentially leading to remote code execution, deletion of system,
personal, or application files, thus impacting the integrity and
availability of the system. The issue arises from the function’s handling
of tar file extraction without performing security checks on the paths
within the tar file, as demonstrated by the ability to overwrite the
/home/kali/.ssh/authorized_keys file by specifying an absolute path in
the malicious tar file.

OSVersionArchitecturePackageVersionFilename
ubuntu22.04noarchonnx< anyUNKNOWN
ubuntu24.04noarchonnx< anyUNKNOWN

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

9

Confidence

High

EPSS

0

Percentile

10.5%