PT-2024-2452 · Mate+1 · Engrampa+1

Febinrev

·

Published

2024-02-05

·

Updated

2024-05-17

·

CVE-2023-52138

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Engrampa versions prior to the version that includes commit 63d5dfa
Description The issue is related to a Path Traversal vulnerability in Engrampa, an archive manager for the MATE environment. This vulnerability can be leveraged to achieve full Remote Command Execution (RCE) on the target. When handling CPIO archives, Engrampa follows symlinks by default, and the Archiver does not check the symlink location, leading to arbitrary file writes to unintended locations. An attacker can craft a malicious cpio or ISO archive to achieve RCE on the target system.
Recommendations For versions prior to the version that includes commit 63d5dfa, update to a version that includes the fix commit 63d5dfa to resolve the issue. As a temporary workaround, consider disabling the extraction of CPIO archives or restricting the use of the Engrampa Archive manager until a patch is available. Avoid using Engrampa to extract archives from untrusted sources until the issue is resolved.

Exploit

Fix

RCE

Path traversal

Link Following

Weakness Enumeration

Related Identifiers

BDU:2024-02421
CVE-2023-52138
DLA-3741-1
DSA-5625-1
GHSA-C98H-V39W-3R7V
OESA-2024-1588
OESA-2024-1589
OPENSUSE-SU-2024:13747-1

Affected Products

Engrampa
Red Os