Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2021-23177
Description:An improper link resolution flaw while extracting an archive can lead to changing the access control list (ACL) of the target of the link. An attacker may provide a malicious archive to a victim user, who would trigger this flaw when trying to extract the archive. A local attacker may use this flaw to change the ACL of a file on the system and gain more privileges.
Test IDs: 1.3.6.1.4.1.25623.1.1.4.2022.3306.1   1.3.6.1.4.1.25623.1.0.892987   1.3.6.1.4.1.25623.1.0.822544   1.3.6.1.4.1.25623.1.0.893202   1.3.6.1.4.1.25623.1.0.854995   1.3.6.1.4.1.25623.1.1.4.2022.3393.1  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2021-23177
https://access.redhat.com/security/cve/CVE-2021-23177
https://access.redhat.com/security/cve/CVE-2021-23177
https://bugzilla.redhat.com/show_bug.cgi?id=2024245
https://bugzilla.redhat.com/show_bug.cgi?id=2024245
https://github.com/libarchive/libarchive/commit/fba4f123cc456d2b2538f811bb831483bf336bad
https://github.com/libarchive/libarchive/commit/fba4f123cc456d2b2538f811bb831483bf336bad
https://github.com/libarchive/libarchive/issues/1565
https://github.com/libarchive/libarchive/issues/1565
https://lists.debian.org/debian-lts-announce/2022/11/msg00030.html




© 1998-2025 E-Soft Inc. All rights reserved.