oss-sec mailing list archives
vulnerabilities in busybox tar and cpio tools
From: Ian Norton <Ian.Norton () entrust com>
Date: Wed, 23 Apr 2025 14:11:44 +0000
https://bugs.busybox.net/show_bug.cgi?id=16018 (awaiting CVE) Busybox's cpio and tar tools will print un-escaped filenames when listing and unpacking cpio and tar files. Malicious files containing filenames with terminal escapes can be used to mask or modify earlier or later files in the archive from anyone running busybox tar or cpio from a terminal. see also https://lists.busybox.net/pipermail/busybox/2024-July/090806.html https://security-tracker.debian.org/tracker/CVE-2023-39810 A unpacking a cpio archive can escape the working directory. Due to #16018 it is possible to mask these traversals from anyone using cpio to inspect a file before unpacking. see also https://lists.busybox.net/pipermail/busybox/2024-July/090851.html Any email and files/attachments transmitted with it are intended solely for the use of the individual or entity to whom they are addressed. If this message has been sent to you in error, you must not copy, distribute or disclose of the information it contains. Please notify Entrust immediately and delete the message from your system.
Current thread:
- vulnerabilities in busybox tar and cpio tools Ian Norton (Apr 23)
- Re: vulnerabilities in busybox tar and cpio tools Ricardo Branco (Apr 23)
- Re: vulnerabilities in busybox tar and cpio tools Salvatore Bonaccorso (Apr 23)
- Re: vulnerabilities in busybox tar and cpio tools Albert Veli (Apr 24)
- Re: [EXTERNAL] Re: [oss-security] vulnerabilities in busybox tar and cpio tools Ian Norton (Apr 24)
- Re: vulnerabilities in busybox tar and cpio tools Demi Marie Obenour (Apr 24)
- Re: vulnerabilities in busybox tar and cpio tools Solar Designer (Apr 24)
- Re: vulnerabilities in busybox tar and cpio tools Demi Marie Obenour (Apr 25)
- Re: vulnerabilities in busybox tar and cpio tools Salvatore Bonaccorso (Apr 23)
- Re: vulnerabilities in busybox tar and cpio tools Ricardo Branco (Apr 23)
- Re: [EXTERNAL] Re: [oss-security] vulnerabilities in busybox tar and cpio tools Ian Norton (Apr 24)
