UBUNTU-CVE-2021-3907

Source
https://ubuntu.com/security/CVE-2021-3907
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-3907.json
JSON Data
https://api.test.osv.dev/v1/vulns/UBUNTU-CVE-2021-3907
Related
Published
2021-11-11T22:15:00Z
Modified
2021-11-11T22:15:00Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

OctoRPKI does not escape a URI with a filename containing "..", this allows a repository to create a file, (ex. rsync://example.org/repo/../../etc/cron.daily/evil.roa), which would then be written to disk outside the base cache folder. This could allow for remote code execution on the host machine OctoRPKI is running on.

References

Affected packages

Ubuntu:22.04:LTS / cfrpki

Package

Name
cfrpki
Purl
pkg:deb/ubuntu/cfrpki?arch=src?distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.4.2-1

Affected versions

1.*

1.2.2-1
1.3.0-1
1.4.0-1

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "medium",
    "binaries": [
        {
            "binary_version": "1.4.2-1",
            "binary_name": "octorpki"
        },
        {
            "binary_version": "1.4.2-1",
            "binary_name": "octorpki-dbgsym"
        }
    ]
}