A path traversal vulnerability affects yaffshiv YAFFS filesystem extractor. By crafting a malicious YAFFS file, an attacker could force yaffshiv to write outside of the extraction directory.
This issue affects yaffshiv up to version 0.1 included, which is the most recent at time of publication.
References
Link | Resource |
---|---|
https://github.com/devttys0/yaffshiv/pull/3/files | Patch Third Party Advisory |
https://onekey.com/blog/security-advisory-remote-command-execution-in-binwalk/ | Exploit Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: ONEKEY
Published: 2023-01-31T09:31:44.677Z
Updated:
Reserved: 2023-01-31T09:26:04.691Z
Link: CVE-2023-0593
JSON object: View
NVD Information
Status : Modified
Published: 2023-01-31T10:15:10.450
Modified: 2023-11-07T04:00:56.343
Link: CVE-2023-0593
JSON object: View
Redhat Information
No data.
CWE