PT-2022-11722 · Refirm+2 · Binwalk+2
Devttys0
·
Published
2022-12-27
·
Updated
2025-01-27
·
CVE-2021-4287
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
ReFirm Labs binwalk versions up to 2.3.2
Description
A problematic issue was found in the Archive Extraction Handler component, specifically in the file src/binwalk/modules/extractor.py. The manipulation leads to symlink following, and it is possible to launch the attack remotely.
Recommendations
For ReFirm Labs binwalk versions up to 2.3.2, upgrade to version 2.3.3 to address this issue.
Fix
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Debian
Binwalk