#VU61393 UNIX symbolic link following in libarchive - CVE-2021-23177
Published: March 15, 2022
libarchive
libarchive
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a symlink following issue when extracting files from archive, which can lean to changing ACLs of the target of the link. A local user can create a specially crafted archive, trick the victim into extracting files from it and escalate privileges on the system.