PT-2023-14603 · Refirm+2 · Binwalk+2
Qkaiser
+1
·
Publicado
2023-01-25
·
Atualizado
2025-12-16
·
CVE-2022-4510
CVSS v3.1
7.8
Alta
| Vetor | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
binwalk versions 2.1.2b through 2.3.3
Description
binwalk is susceptible to a path traversal vulnerability. An attacker can exploit this by crafting a malicious PFS filesystem file, which allows them to extract files to arbitrary locations when binwalk is run in extraction mode (using the -e option). This can lead to remote code execution by extracting a malicious binwalk module into the
.config/binwalk/plugins folder. The vulnerability is associated with the src/binwalk/plugins/unpfs.py file.Recommendations
Upgrade to a version of binwalk newer than 2.3.3.
Exploit
Correção
RCE
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Debian
Binwalk