CVE-2022-4510
Summary
| CVE | CVE-2022-4510 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-01-26 21:18:00 UTC |
| Updated | 2023-09-17 09:15:00 UTC |
| Description | A path traversal vulnerability was identified in ReFirm Labs binwalk from version 2.1.2b through 2.3.3 included. By crafting a malicious PFS filesystem file, an attacker can get binwalk's PFS extractor to extract files at arbitrary locations when binwalk is run in extraction mode (-e option). Remote code execution can be achieved by building a PFS filesystem that, upon extraction, would extract a malicious binwalk module into the folder .config/binwalk/plugins. This vulnerability is associated with program files src/binwalk/plugins/unpfs.py. This issue affects binwalk from 2.1.2b through 2.3.3 included. |
Risk And Classification
Problem Types: CWE-22
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Binwalk: Multiple Vulnerabilities (GLSA 202309-07) — Gentoo security | MISC | security.gentoo.org | |
| fix path traversal in PFS extractor script by QKaiser · Pull Request #617 · ReFirmLabs/binwalk · GitHub | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 181606 Debian Security Update for binwalk (DLA 3339-1)
- 184847 Debian Security Update for binwalk (CVE-2022-4510)
- 283675 Fedora Security Update for binwalk (FEDORA-2023-23047a5f4f)
- 283676 Fedora Security Update for binwalk (FEDORA-2023-32eb9d8ee7)
- 710747 Gentoo Linux Binwalk Multiple Vulnerabilities (GLSA 202309-07)