An improper link resolution flaw can occur while extracting an archive leading to changing modes, times, access control lists, and flags of a file outside of the archive. An attacker may provide a malicious archive to a victim user, who would trigger this flaw when trying to extract the archive. A local attacker may use this flaw to gain more privileges in a system.
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Libarchive | Libarchive | * | 3.5.2 (excluding) |
Libarchive | Ubuntu | bionic | * |
Libarchive | Ubuntu | esm-infra/bionic | * |
Libarchive | Ubuntu | focal | * |
Libarchive | Ubuntu | hirsute | * |
Libarchive | Ubuntu | impish | * |
Libarchive | Ubuntu | trusty | * |
Libarchive | Ubuntu | trusty/esm | * |
Libarchive | Ubuntu | upstream | * |
Libarchive | Ubuntu | xenial | * |
Red Hat Enterprise Linux 8 | RedHat | libarchive-0:3.3.3-3.el8_5 | * |