PT-2021-23582 · Openrc · Openrc

Gary E. Miller

·

Published

2021-10-14

·

Updated

2021-10-20

·

CVE-2021-42341

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions OpenRC versions prior to 0.44.7
Description The issue arises from the checkpath function in OpenRC, which uses the direct output of strlen() to allocate strings. This approach fails to account for the 0 byte at the end of the string, resulting in memory corruption.
Recommendations For OpenRC versions prior to 0.44.7, update to version 0.44.7 or later to resolve the issue. As a temporary workaround, consider restricting the use of the checkpath function until a patch is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2021-42341

Affected Products

Openrc