Alpine: squashfs-tools: security update to 4.5-r0 (deprecated)

high Tenable Self-Hosted Container Security Plugin ID 409773

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- squashfs_opendir in unsquash-2.c in Squashfs-Tools 4.5 allows Directory Traversal, a different
vulnerability than CVE-2021-40153. A squashfs filesystem that has been crafted to include a symbolic link
and then contents under the same filename in a filesystem can cause unsquashfs to first create the
symbolic link pointing outside the expected directory, and then the subsequent write operation will cause
the unsquashfs process to write through the symbolic link elsewhere in the filesystem. (CVE-2021-41072)

See Also

https://git.alpinelinux.org/aports/commit/?id=973439266acaeea4d303ee121772db7f473499cd

https://git.alpinelinux.org/aports/commit/?id=cd66d04ba0ec43c5d5dbb05d2484047820670260

Plugin Details

Severity: High

ID: 409773

Version: Revision 1.25

Type: Local

Published: 10/5/2022

Updated: 1/17/2024

Supported Sensors: Agentless Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.3

Percentile: 53.06

CVSS v2

Risk Factor: Medium

Base Score: 5.8

Temporal Score: 4.5

Vector: CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:P

CVSS Score Source: CVE-2021-41072

CVSS v3

Risk Factor: High

Base Score: 8.1

Temporal Score: 7.3

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 11/9/2021

Vulnerability Publication Date: 9/14/2021

Reference Information

CVE: CVE-2021-41072