Path traversal in engrampa - CVE-2023-52138
Published: February 7, 2024
Vulnerability identifier: #VU86234
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-52138
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to input validation error when handling cpio archives. A remote attacker can pass a specially crafted cpio archive to the application and overwrite arbitrary files on the system, resulting in remote code execution.
Affected software
engrampa
Debian Linux
Fedora
openEuler
engrampa (Debian package)
engrampa
engrampa-debugsource
engrampa-debuginfo
Debian Linux
Fedora
openEuler
engrampa (Debian package)
engrampa
engrampa-debugsource
engrampa-debuginfo
How to mitigate CVE-2023-52138
Install update from vendor's website.
engrampa - update to 1.26.2
engrampa (Debian package) - addressed in versions 1.24.1-1+deb11u1, 1.26.0-1+deb12u2
engrampa - update to 1.24.1-4
engrampa-debugsource - update to 1.24.1-4
engrampa-debuginfo - update to 1.24.1-4
engrampa - addressed in versions 1.26.2-1.el8, 1.26.2-1.el9, 1.26.2-1.fc38, 1.26.2-1.fc39
engrampa (Debian package) - addressed in versions 1.24.1-1+deb11u1, 1.26.0-1+deb12u2
engrampa - update to 1.24.1-4
engrampa-debugsource - update to 1.24.1-4
engrampa-debuginfo - update to 1.24.1-4
engrampa - addressed in versions 1.26.2-1.el8, 1.26.2-1.el9, 1.26.2-1.fc38, 1.26.2-1.fc39