UNIX symbolic link following in libarchive - CVE-2021-23177

 

UNIX symbolic link following in libarchive - CVE-2021-23177

Published: March 15, 2022


Vulnerability identifier: #VU61393
CSH Severity: Low
CVSS v4: 7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-23177
CWE-ID: CWE-61
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to a symlink following issue when extracting files from archive, which can lean to changing ACLs of the target of the link. A local user can create a specially crafted archive, trick the victim into extracting files from it and escalate privileges on the system.


Affected software

libarchive
Red Hat OpenShift GitOps
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
Traffix SDC
Cloud Pak for Security (CP4S)
IBM Qradar SIEM
Red Hat Advanced Cluster Management for Kubernetes
Ansible Automation Platform
Red Hat Advanced Cluster Security for Kubernetes
Netcool Operations Insight
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Linux Enterprise Storage
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat CodeReady Linux Builder for x86_64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for IBM z Systems
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Server
SUSE Linux Enterprise Module for Development Tools
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Desktop
openSUSE Leap
openEuler
Ubuntu
BIG-IQ Centralized Management
BIG-IP
Red Hat OpenShift Serverless
OpenShift Virtualization
libarchive (Red Hat package)
libarchive
bsdtar
libarchive13 (Ubuntu package)
libarchive13-32bit-debuginfo
libarchive13-32bit
libarchive13-debuginfo
libarchive13
libarchive-devel
libarchive-debugsource
bsdtar-debuginfo
libarchive-help
libarchive-debuginfo

How to mitigate CVE-2021-23177

Install updates from vendor's website.

libarchive - update to 3.5.2
Red Hat OpenShift GitOps - addressed in versions 1.2.3, 1.3.6, 1.4.4
Migration Toolkit for Containers - addressed in versions 1.5.4, 1.7.1, 1.7.4
Cloud Pak for Security (CP4S) - update to 1.10.7.0
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.3.8, 2.4.3
Red Hat Advanced Cluster Security for Kubernetes - update to 3.68.2
Red Hat OpenShift Container Platform - addressed in versions 4.11.0, 4.11.45
IBM Qradar SIEM - addressed in versions 7.3.3 Fix Pack 12, 7.4.3 Fix Pack 6, 7.5.0 Update Pack 2
Red Hat OpenShift Serverless - update to 1
Netcool Operations Insight - update to 1.6.6
libarchive (Red Hat package) - update to 3.3.3-3.el8_5
libarchive - update to 3.3.3-3.0.1
bsdtar - update to 3.3.3-3.0.1
libarchive13 (Ubuntu package) - addressed in versions 3.4.0-2ubuntu1.1, 3.4.3-2ubuntu0.1
libarchive13-32bit-debuginfo - addressed in versions 3.4.2-150200.4.9.1, 3.5.1-150400.3.6.1
libarchive13-32bit - addressed in versions 3.4.2-150200.4.9.1, 3.5.1-150400.3.6.1
libarchive13-debuginfo - addressed in versions 3.4.2-150200.4.9.1, 3.5.1-150400.3.6.1
libarchive13 - addressed in versions 3.4.2-150200.4.9.1, 3.5.1-150400.3.6.1
libarchive-devel - addressed in versions 3.4.2-150200.4.9.1, 3.5.1-150400.3.6.1
libarchive-debugsource - addressed in versions 3.4.2-150200.4.9.1, 3.5.1-150400.3.6.1
bsdtar-debuginfo - addressed in versions 3.4.2-150200.4.9.1, 3.5.1-150400.3.6.1
bsdtar - addressed in versions 3.4.2-150200.4.9.1, 3.5.1-150400.3.6.1
libarchive-help - update to 3.4.3-4
libarchive-devel - update to 3.4.3-4
libarchive-debugsource - update to 3.4.3-4
libarchive-debuginfo - update to 3.4.3-4
libarchive - update to 3.4.3-4
OpenShift Virtualization - update to 4.11.0

External References

Related Security Bulletins