Bug ID 1206728
Summary VUL-0: CVE-2021-4287: binwalk: symlink directory traversal vulnerability
Classification openSUSE
Product openSUSE Distribution
Version Leap 15.4
Hardware Other
URL https://smash.suse.de/issue/351915/
OS Other
Status NEW
Severity Minor
Priority P5 - None
Component Security
Assignee boris@steki.net
Reporter carlos.lopez@suse.com
QA Contact security-team@suse.de
Found By Security Response Team
Blocker ---

rh#2156565

A vulnerability, which was classified as problematic, was found in ReFirm Labs
binwalk up to 2.3.2. Affected is an unknown function of the file
src/binwalk/modules/extractor.py of the component Archive Extraction Handler.
The manipulation leads to symlink following. It is possible to launch the
attack remotely. Upgrading to version 2.3.3 is able to address this issue. The
name of the patch is fa0c0bd59b8588814756942fe4cb5452e76c1dcd. It is
recommended to upgrade the affected component. The identifier of this
vulnerability is VDB-216876.

Reference:
https://vuldb.com/?id.216876

Upstream patch:
https://github.com/ReFirmLabs/binwalk/pull/556
https://github.com/ReFirmLabs/binwalk/commit/fa0c0bd59b8588814756942fe4cb5452e76c1dcd

References:
https://bugzilla.redhat.com/show_bug.cgi?id=2156565
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-4287
https://github.com/ReFirmLabs/binwalk/commit/fa0c0bd59b8588814756942fe4cb5452e76c1dcd
https://www.cve.org/CVERecord?id=CVE-2021-4287
https://github.com/ReFirmLabs/binwalk/pull/556
https://github.com/ReFirmLabs/binwalk/releases/tag/v2.3.3
https://vuldb.com/?id.216876
https://vuldb.com/?ctiid.216876


You are receiving this mail because: