// For flags

CVE-2023-38346

 

Severity Score

8.8
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

Attend
*SSVC
Descriptions

An issue was discovered in Wind River VxWorks 6.9 and 7. The function ``tarExtract`` implements TAR file extraction and thereby also processes files within an archive that have relative or absolute file paths. A developer using the "tarExtract" function may expect that the function will strip leading slashes from absolute paths or stop processing when encountering relative paths that are outside of the extraction path, unless otherwise forced. This could lead to unexpected and undocumented behavior, which in general could result in a directory traversal, and associated unexpected behavior.

Se descubrió un problema en Wind River VxWorks 6.9 y 7. La función ``tarExtract`` implementa la extracción de archivos TAR y, por lo tanto, también procesa archivos dentro de un archivo que tienen rutas de archivo relativas o absolutas. Un desarrollador que utilice la función "tarExtract" puede esperar que la función elimine las barras diagonales iniciales de las rutas absolutas o detenga el procesamiento cuando encuentre rutas relativas que estén fuera de la ruta de extracción, a menos que se fuerce lo contrario. Esto podría dar lugar a un comportamiento inesperado y no documentado, que en general podría dar lugar a un Directory Traversal y un comportamiento inesperado asociado.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
* Common Vulnerability Scoring System
SSVC
  • Decision:Attend
Exploitation
Poc
Automatable
No
Tech. Impact
Total
* Organization's Worst-case Scenario
Timeline
  • 2023-07-15 CVE Reserved
  • 2023-09-22 CVE Published
  • 2024-09-25 CVE Updated
  • 2024-09-25 First Exploit
  • 2024-09-28 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Windriver
Search vendor "Windriver"
Vxworks
Search vendor "Windriver" for product "Vxworks"
6.9
Search vendor "Windriver" for product "Vxworks" and version "6.9"
-
Affected
Windriver
Search vendor "Windriver"
Vxworks
Search vendor "Windriver" for product "Vxworks"
7.0
Search vendor "Windriver" for product "Vxworks" and version "7.0"
-
Affected