Wind River Support Network

HomeDefectsLIN1021-4912
Fixed

LIN1021-4912 : Security Advisory - go - CVE-2022-41722

Created: Dec 12, 2022    Updated: May 2, 2023
Resolved Date: May 2, 2023
Found In Version: 10.21.20.1
Severity: Standard
Applicable for: Wind River Linux LTS 21
Component/s: Userspace

Description

A path traversal vulnerability exists in filepath.Clean on Windows. On Windows, the filepath.Clean function could transform an invalid path such as "a/../c:/b" into the valid path "c:\b". This transformation of a relative (if invalid) path into an absolute path could enable a directory traversal attack. After fix, the filepath.Clean function transforms this path into the relative (but still invalid) path ".\c:\b".

https://nvd.nist.gov/vuln/detail/CVE-2022-41722
Live chat
Online