{"api_version":"1","generated_at":"2026-07-23T22:02:12+00:00","cve":"CVE-2021-41072","urls":{"html":"https://cve.report/CVE-2021-41072","api":"https://cve.report/api/cve/CVE-2021-41072.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-41072","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-41072"},"summary":{"title":"CVE-2021-41072","description":"squashfs_opendir in unsquash-2.c in Squashfs-Tools 4.5 allows Directory Traversal, a different vulnerability than CVE-2021-40153. A squashfs filesystem that has been crafted to include a symbolic link and then contents under the same filename in a filesystem can cause unsquashfs to first create the symbolic link pointing outside the expected directory, and then the subsequent write operation will cause the unsquashfs process to write through the symbolic link elsewhere in the filesystem.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2021-09-14 01:15:00","updated_at":"2023-05-30 06:15:00"},"problem_types":["CWE-22","CWE-59"],"metrics":[],"references":[{"url":"https://security.gentoo.org/glsa/202305-29","name":"GLSA-202305-29","refsource":"GENTOO","tags":[],"title":"squashfs-tools: Multiple Vulnerabilities (GLSA 202305-29) — Gentoo security","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://github.com/plougher/squashfs-tools/issues/72#issuecomment-913833405","name":"https://github.com/plougher/squashfs-tools/issues/72#issuecomment-913833405","refsource":"MISC","tags":[],"title":"unsquashfs - unvalidated filepaths allow writing outside of destination · Issue #72 · plougher/squashfs-tools · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://lists.debian.org/debian-lts-announce/2021/10/msg00017.html","name":"[debian-lts-announce] 20211020 [SECURITY] [DLA 2789-1] squashfs-tools security update","refsource":"MLIST","tags":[],"title":"[SECURITY] [DLA 2789-1] squashfs-tools security update","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://github.com/plougher/squashfs-tools/commit/e0485802ec72996c20026da320650d8362f555bd","name":"https://github.com/plougher/squashfs-tools/commit/e0485802ec72996c20026da320650d8362f555bd","refsource":"MISC","tags":[],"title":"Unsquashfs: additional write outside destination directory exploit fix · plougher/squashfs-tools@e048580 · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.debian.org/security/2021/dsa-4987","name":"DSA-4987","refsource":"DEBIAN","tags":[],"title":"Debian -- Security Information -- DSA-4987-1 squashfs-tools","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-41072","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-41072","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2021","cve_id":"41072","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"debian","cpe5":"debian_linux","cpe6":"10.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"41072","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"debian","cpe5":"debian_linux","cpe6":"11.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"41072","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"debian","cpe5":"debian_linux","cpe6":"9.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"41072","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"squashfs-tools_project","cpe5":"squashfs-tools","cpe6":"4.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2021-41072","qid":"178823","title":"Debian Security Update for squashfs-tools (DSA 4987-1)"},{"cve":"CVE-2021-41072","qid":"178845","title":"Debian Security Update for squashfs-tools (DLA 2789-1)"},{"cve":"CVE-2021-41072","qid":"184431","title":"Debian Security Update for squashfs-tools (CVE-2021-41072)"},{"cve":"CVE-2021-41072","qid":"198500","title":"Ubuntu Security Notification for Squashfs-Tools Vulnerability (USN-5078-1)"},{"cve":"CVE-2021-41072","qid":"198537","title":"Ubuntu Security Notification for Squashfs-Tools Vulnerability (USN-5078-3)"},{"cve":"CVE-2021-41072","qid":"355609","title":"Amazon Linux Security Advisory for squashfs-tools : ALAS2-2023-2152"},{"cve":"CVE-2021-41072","qid":"501784","title":"Alpine Linux Security Update for squashfs-tools"},{"cve":"CVE-2021-41072","qid":"504425","title":"Alpine Linux Security Update for squashfs-tools"},{"cve":"CVE-2021-41072","qid":"671158","title":"EulerOS Security Update for squashfs-tools (EulerOS-SA-2021-2814)"},{"cve":"CVE-2021-41072","qid":"671188","title":"EulerOS Security Update for squashfs-tools (EulerOS-SA-2021-2936)"},{"cve":"CVE-2021-41072","qid":"671216","title":"EulerOS Security Update for squashfs-tools (EulerOS-SA-2022-1019)"},{"cve":"CVE-2021-41072","qid":"671226","title":"EulerOS Security Update for squashfs-tools (EulerOS-SA-2022-1039)"},{"cve":"CVE-2021-41072","qid":"671232","title":"EulerOS Security Update for squashfs-tools (EulerOS-SA-2022-1189)"},{"cve":"CVE-2021-41072","qid":"671285","title":"EulerOS Security Update for squashfs-tools (EulerOS-SA-2022-1216)"},{"cve":"CVE-2021-41072","qid":"671297","title":"EulerOS Security Update for squashfs-tools (EulerOS-SA-2022-1235)"},{"cve":"CVE-2021-41072","qid":"710736","title":"Gentoo Linux squashfs-tools Multiple Vulnerabilities (GLSA 202305-29)"},{"cve":"CVE-2021-41072","qid":"755254","title":"SUSE Enterprise Linux Security Update for squashfs (SUSE-SU-2023:4424-1)"},{"cve":"CVE-2021-41072","qid":"755351","title":"SUSE Enterprise Linux Security Update for squashfs (SUSE-SU-2023:4591-1)"},{"cve":"CVE-2021-41072","qid":"901101","title":"Common Base Linux Mariner (CBL-Mariner) Security Update for squashfs-tools (7464-1)"}]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2021-41072","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"squashfs_opendir in unsquash-2.c in Squashfs-Tools 4.5 allows Directory Traversal, a different vulnerability than CVE-2021-40153. A squashfs filesystem that has been crafted to include a symbolic link and then contents under the same filename in a filesystem can cause unsquashfs to first create the symbolic link pointing outside the expected directory, and then the subsequent write operation will cause the unsquashfs process to write through the symbolic link elsewhere in the filesystem."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"url":"https://github.com/plougher/squashfs-tools/commit/e0485802ec72996c20026da320650d8362f555bd","refsource":"MISC","name":"https://github.com/plougher/squashfs-tools/commit/e0485802ec72996c20026da320650d8362f555bd"},{"url":"https://github.com/plougher/squashfs-tools/issues/72#issuecomment-913833405","refsource":"MISC","name":"https://github.com/plougher/squashfs-tools/issues/72#issuecomment-913833405"},{"refsource":"DEBIAN","name":"DSA-4987","url":"https://www.debian.org/security/2021/dsa-4987"},{"refsource":"MLIST","name":"[debian-lts-announce] 20211020 [SECURITY] [DLA 2789-1] squashfs-tools security update","url":"https://lists.debian.org/debian-lts-announce/2021/10/msg00017.html"},{"refsource":"GENTOO","name":"GLSA-202305-29","url":"https://security.gentoo.org/glsa/202305-29"}]}},"nvd":{"publishedDate":"2021-09-14 01:15:00","lastModifiedDate":"2023-05-30 06:15:00","problem_types":["CWE-22","CWE-59"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.1,"baseSeverity":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.2},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:P","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":5.8},"severity":"MEDIUM","exploitabilityScore":8.6,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:squashfs-tools_project:squashfs-tools:4.5:*:*:*:*:*:*:*","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"41072","Ordinal":"216844","Title":"CVE-2021-41072","CVE":"CVE-2021-41072","Year":"2021"},"notes":[{"CveYear":"2021","CveId":"41072","Ordinal":"1","NoteData":"squashfs_opendir in unsquash-2.c in Squashfs-Tools 4.5 allows Directory Traversal, a different vulnerability than CVE-2021-40153. A squashfs filesystem that has been crafted to include a symbolic link and then contents under the same filename in a filesystem can cause unsquashfs to first create the symbolic link pointing outside the expected directory, and then the subsequent write operation will cause the unsquashfs process to write through the symbolic link elsewhere in the filesystem.","Type":"Description","Title":null},{"CveYear":"2021","CveId":"41072","Ordinal":"2","NoteData":"2021-09-13","Type":"Other","Title":"Published"},{"CveYear":"2021","CveId":"41072","Ordinal":"3","NoteData":"2021-10-20","Type":"Other","Title":"Modified"}]}}}