Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2021-40153
Description:squashfs_opendir in unsquash-1.c in Squashfs-Tools 4.5 stores the filename in the directory entry; this is then used by unsquashfs to create the new file during the unsquash. The filename is not validated for traversal outside of the destination directory, and thus allows writing to locations outside of the destination.
Test IDs: 1.3.6.1.4.1.25623.1.0.704967   1.3.6.1.4.1.25623.1.0.845043   1.3.6.1.4.1.25623.1.1.2.2021.2904   1.3.6.1.4.1.25623.1.1.2.2022.1096   1.3.6.1.4.1.25623.1.0.818467   1.3.6.1.4.1.25623.1.1.2.2021.2645   1.3.6.1.4.1.25623.1.0.818730   1.3.6.1.4.1.25623.1.0.892752   1.3.6.1.4.1.25623.1.1.2.2021.2674   1.3.6.1.4.1.25623.1.1.2.2021.2748   1.3.6.1.4.1.25623.1.1.2.2021.2854   1.3.6.1.4.1.25623.1.1.2.2021.2774   1.3.6.1.4.1.25623.1.1.2.2021.2698   1.3.6.1.4.1.25623.1.1.2.2021.2723  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2021-40153
Debian Security Information: DSA-4967 (Google Search)
https://www.debian.org/security/2021/dsa-4967
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GSMRKVJMJFX3MB7D3PXJSYY3TLZROE5S/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RAOZ4BKWAC4Y3U2K5MMW3S77HWWXHQDL/
https://security.gentoo.org/glsa/202305-29
https://bugs.launchpad.net/ubuntu/+source/squashfs-tools/+bug/1941790
https://github.com/plougher/squashfs-tools/commit/79b5a555058eef4e1e7ff220c344d39f8cd09646
https://github.com/plougher/squashfs-tools/issues/72
https://lists.debian.org/debian-lts-announce/2021/08/msg00030.html




© 1998-2025 E-Soft Inc. All rights reserved.