Path traversal in engrampa - CVE-2023-52138

 

Path traversal in engrampa - CVE-2023-52138

Published: February 7, 2024


Vulnerability identifier: #VU86234
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-52138
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to input validation error when handling cpio archives. A remote attacker can pass a specially crafted cpio archive to the application and overwrite arbitrary files on the system, resulting in remote code execution.


Affected software

engrampa
Debian Linux
Fedora
openEuler
engrampa (Debian package)
engrampa
engrampa-debugsource
engrampa-debuginfo

How to mitigate CVE-2023-52138

Install update from vendor's website.

engrampa - update to 1.26.2
engrampa (Debian package) - addressed in versions 1.24.1-1+deb11u1, 1.26.0-1+deb12u2
engrampa - update to 1.24.1-4
engrampa-debugsource - update to 1.24.1-4
engrampa-debuginfo - update to 1.24.1-4
engrampa - addressed in versions 1.26.2-1.el8, 1.26.2-1.el9, 1.26.2-1.fc38, 1.26.2-1.fc39

External References

Related Security Bulletins