UBUNTU-CVE-2021-3907
Dashboard / Vulnerabilities / UBUNTU-CVE-2021-3907
Summary:
Details: OctoRPKI does not escape a URI with a filename containing "..", this allows a repository to create a file, (ex. rsync://example.org/repo/../../etc/cron.daily/evil.roa), which would then be written to disk outside the base cache folder. This could allow for remote code execution on the host machine OctoRPKI is running on.
References: https://ubuntu.com/security/CVE-2021-3907, https://github.com/cloudflare/cfrpki/security/advisories/GHSA-cqh2-vc2f-q4fh, https://github.com/cloudflare/cfrpki/commit/a053a808feeb3115c76b6cc263ee55598ce6e8cd, https://www.cve.org/CVERecord?id=CVE-2021-3907
Affected packages
Package
Name: fort-validator
Purl: pkg:deb/ubuntu/[email protected]~esm1?arch=source&distro=esm-apps/focal
Affected ranges
Type: ECOSYSTEM
Events:
