PT-2022-11722 · Refirm+2 · Binwalk+2

Devttys0

·

Published

2022-12-27

·

Updated

2025-01-27

·

CVE-2021-4287

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions ReFirm Labs binwalk versions up to 2.3.2
Description A problematic issue was found in the Archive Extraction Handler component, specifically in the file src/binwalk/modules/extractor.py. The manipulation leads to symlink following, and it is possible to launch the attack remotely.
Recommendations For ReFirm Labs binwalk versions up to 2.3.2, upgrade to version 2.3.3 to address this issue.

Fix

Link Following

Weakness Enumeration

Related Identifiers

ALT-PU-2021-4837
ALT-PU-2024-8902
ALT-PU-2025-1936
CVE-2021-4287
GHSA-8M3F-G62J-3VX8

Affected Products

Alt Linux
Debian
Binwalk