Wind River Support Network

HomeDefectsLIN1018-10099
Fixed

LIN1018-10099 : Security Advisory - go - CVE-2022-41722

Created: Dec 12, 2022    Updated: May 2, 2023
Resolved Date: May 2, 2023
Found In Version: 10.18.44.1
Severity: Standard
Applicable for: Wind River Linux LTS 18
Component/s: Userspace

Description

A path traversal vulnerability exists in filepath.Clean on Windows. On Windows, the filepath.Clean function could transform an invalid path such as "a/../c:/b" into the valid path "c:\b". This transformation of a relative (if invalid) path into an absolute path could enable a directory traversal attack. After fix, the filepath.Clean function transforms this path into the relative (but still invalid) path ".\c:\b".

https://nvd.nist.gov/vuln/detail/CVE-2022-41722
Live chat
Online