QID 375847

Date Published: 2021-09-20

QID 375847: Alpine Linux Alpine Package Keeper (APK) Remote Code Execution Vulnerability

Alpine Linux is an independent, non-commercial, general-purpose Linux distribution designed for power users who appreciate security, simplicity, and resource efficiency.

A vulnerability in the apk-tools package used by Alpine Linux could allow an unauthenticated, remote attacker to execute arbitrary code on a targeted system.
The vulnerability exists because the affected software improperly handles symbolic and hard file links when extracting the contents of an Alpine Package Keeper (APK) file.

Affected Versions:
Alpine Linux apk-tools 2.7.7 to 2.10.0
Alpine Linux apk-tools 2.7.0 to 2.7.5
Alpine Linux apk-tools upto 2.6.9

QID Detection Logic(Authenticated):

A successful exploit could allow the attacker to execute arbitrary code and completely compromise the system.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as High - 6.8 severity.
  • Solution
    Customers are advised to download the latest version of apk-tools 2.10.1 or later.
    For more information, visit Alpine Linux apk-tools.
    Vendor References

    CVEs related to QID 375847

    Software Advisories
    Advisory ID Software Component Link
    Alpine Linux URL Logo stack.watch/product/alpinelinux/