← Back

CVE-2021-31566

nvd nist
Published: Aug 23, 2022Modified: Jun 17, 2026

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

An improper link resolution flaw can occur while extracting an archive leading to changing modes, times, access control lists, and flags of a file outside of the archive. An attacker may provide a malicious archive to a victim user, who would trigger this flaw when trying to extract the archive. A local attacker may use this flaw to gain more privileges in a system.

Affected (10)

Show all products
1 product
Libarchive
1 product
Fedora
4 products
1 product
Debian Linux
1 product
Universal Forwarder
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 3.5.2
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 35
Configuration C
3 vulnerable
Configuration D
1 vulnerable · 6 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Redhat
Enterprise Linux
Version 8.0
Redhat
Enterprise Linux Eus
Version 8.6
Redhat
Enterprise Linux For Ibm Z Systems
Version 8.0
Redhat
Enterprise Linux For Ibm Z Systems Eus
Version 8.6
Redhat
Enterprise Linux For Power Little Endian
Version 8.0
Redhat
Enterprise Linux For Power Little Endian Eus
Version 8.6
Configuration E
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 10.0
Configuration F
3 vulnerable
Vulnerable SoftwareAffected Versions
Splunk
From 8.2.0 to 8.2.12
From 9.0.0 to 9.0.6
Version 9.1.0

References (10)

Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Issue TrackingPatchThird Party Advisory
Source: secalert@redhat.com
Issue TrackingPatchThird Party Advisory
Source: secalert@redhat.com
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory

Timeline

No history available yet.