Advisory Database
  • Advisories
  • Dependency Scanning
  1. conan
  2. ›
  3. libarchive
  4. ›
  5. CVE-2021-31566

CVE-2021-31566: Improper Link Resolution Before File Access ('Link Following')

August 23, 2022 (updated December 3, 2022)

An improper link resolution flaw can occur while extracting an archive leading to changing modes, times, access control lists, and flags of a file outside of the archive. An attacker may provide a malicious archive to a victim user, who would trigger this flaw when trying to extract the archive. A local attacker may use this flaw to gain more privileges in a system.

References

  • access.redhat.com/security/cve/CVE-2021-31566
  • bugzilla.redhat.com/show_bug.cgi?id=2024237
  • github.com/libarchive/libarchive/commit/b41daecb5ccb4c8e3b2c53fd6147109fc12c3043
  • github.com/libarchive/libarchive/issues/1566
  • nvd.nist.gov/vuln/detail/CVE-2021-31566

Code Behaviors & Features

Detect and mitigate CVE-2021-31566 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 3.5.2

Fixed versions

  • 3.5.2

Solution

Upgrade to version 3.5.2 or above.

Impact 7.8 HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Learn more about CVSS

Weakness

  • CWE-59: Improper Link Resolution Before File Access ('Link Following')

Source file

conan/libarchive/CVE-2021-31566.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 14 May 2025 12:16:14 +0000.