PT-2024-2452 · Mate+1 · Engrampa+1
Febinrev
·
Published
2024-02-05
·
Updated
2024-05-17
·
CVE-2023-52138
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Engrampa versions prior to the version that includes commit 63d5dfa
Description
The issue is related to a Path Traversal vulnerability in Engrampa, an archive manager for the MATE environment. This vulnerability can be leveraged to achieve full Remote Command Execution (RCE) on the target. When handling CPIO archives, Engrampa follows symlinks by default, and the Archiver does not check the symlink location, leading to arbitrary file writes to unintended locations. An attacker can craft a malicious cpio or ISO archive to achieve RCE on the target system.
Recommendations
For versions prior to the version that includes commit 63d5dfa, update to a version that includes the fix commit 63d5dfa to resolve the issue. As a temporary workaround, consider disabling the extraction of CPIO archives or restricting the use of the Engrampa Archive manager until a patch is available. Avoid using Engrampa to extract archives from untrusted sources until the issue is resolved.
Exploit
Fix
RCE
Path traversal
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Engrampa
Red Os