Alexander Cherepanov discovered that libelf1 incorrectly handled certain filesystem paths while extracting ar archives. An attacker could use this flaw to perform a directory traversal attack on the root directory if the process extracting the ar archive has write access to the root directory.
{
"binaries": [
{
"binary_name": "elfutils",
"binary_version": "0.158-0ubuntu5.2"
},
{
"binary_name": "libasm-dev",
"binary_version": "0.158-0ubuntu5.2"
},
{
"binary_name": "libasm1",
"binary_version": "0.158-0ubuntu5.2"
},
{
"binary_name": "libdw-dev",
"binary_version": "0.158-0ubuntu5.2"
},
{
"binary_name": "libdw1",
"binary_version": "0.158-0ubuntu5.2"
},
{
"binary_name": "libelf-dev",
"binary_version": "0.158-0ubuntu5.2"
},
{
"binary_name": "libelf1",
"binary_version": "0.158-0ubuntu5.2"
}
],
"availability": "No subscription required"
}