Show filters
12 Total Results
Displaying 1-10 of 12
Sort by:
Attacker Value
Unknown
CVE-2021-41072
Disclosure Date: September 14, 2021 (last updated February 23, 2025)
squashfs_opendir in unsquash-2.c in Squashfs-Tools 4.5 allows Directory Traversal, a different vulnerability than CVE-2021-40153. A squashfs filesystem that has been crafted to include a symbolic link and then contents under the same filename in a filesystem can cause unsquashfs to first create the symbolic link pointing outside the expected directory, and then the subsequent write operation will cause the unsquashfs process to write through the symbolic link elsewhere in the filesystem.
0
Attacker Value
Unknown
CVE-2021-40153
Disclosure Date: August 27, 2021 (last updated February 23, 2025)
squashfs_opendir in unsquash-1.c in Squashfs-Tools 4.5 stores the filename in the directory entry; this is then used by unsquashfs to create the new file during the unsquash. The filename is not validated for traversal outside of the destination directory, and thus allows writing to locations outside of the destination.
0
Attacker Value
Unknown
CVE-2015-4646
Disclosure Date: April 13, 2017 (last updated November 26, 2024)
(1) unsquash-1.c, (2) unsquash-2.c, (3) unsquash-3.c, and (4) unsquash-4.c in Squashfs and sasquatch allow remote attackers to cause a denial of service (application crash) via a crafted input.
0
Attacker Value
Unknown
CVE-2015-4645
Disclosure Date: March 17, 2017 (last updated November 26, 2024)
Integer overflow in the read_fragment_table_4 function in unsquash-4.c in Squashfs and sasquatch allows remote attackers to cause a denial of service (application crash) via a crafted input, which triggers a stack-based buffer overflow.
0
Attacker Value
Unknown
CVE-2012-4025
Disclosure Date: July 19, 2012 (last updated October 04, 2023)
Integer overflow in the queue_init function in unsquashfs.c in unsquashfs in Squashfs 4.2 and earlier allows remote attackers to execute arbitrary code via a crafted block_log field in the superblock of a .sqsh file, leading to a heap-based buffer overflow.
0
Attacker Value
Unknown
CVE-2012-4024
Disclosure Date: July 19, 2012 (last updated October 04, 2023)
Stack-based buffer overflow in the get_component function in unsquashfs.c in unsquashfs in Squashfs 4.2 and earlier allows remote attackers to execute arbitrary code via a crafted list file (aka a crafted file for the -ef option). NOTE: probably in most cases, the list file is a trusted file constructed by the program's user; however, there are some realistic situations in which a list file would be obtained from an untrusted remote source.
0
Attacker Value
Unknown
CVE-2008-0405
Disclosure Date: January 29, 2008 (last updated October 04, 2023)
Multiple directory traversal vulnerabilities in HTTP File Server (HFS) before 2.2c, when account names are used as log filenames, allow remote attackers to create arbitrary (1) files and (2) directories via a .. (dot dot) in an account name, when requesting the / URI; and (3) append arbitrary data to a file via a .. (dot dot) in an account name, when requesting a URI composed of a "/?%0a" sequence followed by the data.
0
Attacker Value
Unknown
CVE-2008-0406
Disclosure Date: January 29, 2008 (last updated October 04, 2023)
HTTP File Server (HFS) before 2.2c, when account names are used as log filenames, allows remote attackers to cause a denial of service (daemon crash) via a long account name.
0
Attacker Value
Unknown
CVE-2008-0408
Disclosure Date: January 29, 2008 (last updated October 04, 2023)
HTTP File Server (HFS) before 2.2c allows remote attackers to append arbitrary text to the log file by using the base64 representation of this text during HTTP Basic Authentication.
0
Attacker Value
Unknown
CVE-2008-0409
Disclosure Date: January 29, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in HTTP File Server (HFS) before 2.2c allows remote attackers to inject arbitrary web script or HTML via the userinfo subcomponent of a URL.
0