Debian Security Update DSA-4987 squashfs-tools - security update

LinuxBot

Member
Joined
Apr 25, 2017
Messages
5,944
Reaction score
80
Credits
-1,257
Richard Weinberger reported that unsquashfs in squashfs-tools, the tools to create and extract Squashfs filesystems, does not check for duplicate filenames within a directory. An attacker can take advantage of this flaw for writing to arbitrary files to the filesystem if a malformed Squashfs image is processed.

Continue reading...
 


Follow Linux.org

Members online


Top