CVEs (2)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Debian Squashfs Tools Project2Debian Linux Squashfs ToolsNov 21, 2024 Sep 14, 2021 N/A· v4 8.1 HIGH· v3 5.8 MEDIUM· v2 squashfs_opendir in unsquash-2.c in Squashfs-Tools 4.5 allows Directory Traversal, a different vulnerability than CVE-2021-40153. A squashfs filesystem that has been crafted to include a symbolic link and then contents u...Show more |
4Debian FedoraprojectRedhat+1 more4Debian Linux Enterprise LinuxFedora+1 moreNov 21, 2024 Aug 27, 2021 N/A· v4 8.1 HIGH· v3 5.8 MEDIUM· v2 squashfs_opendir in unsquash-1.c in Squashfs-Tools 4.5 stores the filename in the directory entry; this is then used by unsquashfs to create the new file during the unsquash. The filename is not validated for traversal o...Show more |