Wind River Support Network

HomeDefectsLIN1022-308
Fixed

LIN1022-308 : Security Advisory - libarchive - CVE-2021-23177

Created: Apr 29, 2022    Updated: Sep 27, 2022
Resolved Date: Jul 20, 2022
Found In Version: 10.22.33.1
Severity: Standard
Applicable for: Wind River Linux LTS 22
Component/s: Userspace

Description

An improper link resolution flaw while extracting an archive can lead to changing the access control list (ACL) of the target of the link. An attacker may provide a malicious archive to a victim user, who would trigger this flaw when trying to extract the archive. A local attacker may use this flaw to change the ACL of a file on the system and gain more privileges.

https://nvd.nist.gov/vuln/detail/CVE-2021-23177

CVEs


Live chat
Online