Path traversal in BusyBox - CVE-2011-5325

 

Path traversal in BusyBox - CVE-2011-5325

Published: March 24, 2022


Vulnerability identifier: #VU61584
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2011-5325
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform directory traversal attacks.

The vulnerability exists due to input validation error when processing directory traversal sequences in the BusyBox implementation of tar. A remote attacker can trick pass specially crafted tar archive to the application and overwrite files outside the current working directory via a symlink.


Affected software

BusyBox
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Enterprise Storage
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Realtime Extension
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Desktop
openSUSE Leap
R6700v3
CBR40
R6400v2
R7000P
R7000
R6900P
RS400
busybox
busybox-static
busybox-warewulf3
busybox-testsuite

How to mitigate CVE-2011-5325

Install update from vendor's website.

BusyBox - update to 1.22.0
R6700v3 - update to 1.0.4.126
R6400v2 - update to 1.0.4.126
R7000P - update to 1.0.11.134
R7000 - update to 1.0.11.134
R6900P - update to 1.3.3.148
RS400 - update to 1.5.1.86
busybox - addressed in versions 1.26.2-4.5.1, 1.34.1-4.9.1, 1.35.0-4.3.1, 1.35.0-150400.3.3.1
busybox-static - addressed in versions 1.26.2-4.5.1, 1.34.1-4.9.1, 1.35.0-150400.3.3.1
busybox-warewulf3 - update to 1.35.0-150400.3.3.1
busybox-testsuite - update to 1.35.0-150400.3.3.1
CBR40 - update to 2.5.0.28

External References

Related Security Bulletins