Scan for free your assets for this vulnerability
It is easy and free to get started with Mageni and it can be installed in Windows, macOS and Linux.
Processing. Please wait...
No credit card necessary
Debian: Security Advisory for squashfs-tools (DSA-4967-1)
The remote host is missing an update for the 'squashfs-tools' package(s) announced via the DSA-4967-1 advisory.
Etienne Stalmans discovered that unsquashfs in squashfs-tools, the tools to create and extract Squashfs filesystems, does not validate filenames for traversal outside of the destination directory. An attacker can take advantage of this flaw for writing to arbitrary files to the filesystem if a malformed Squashfs image is processed.
'squashfs-tools' package(s) on Debian Linux.
Checks if a vulnerable package version is present on the target host.
For the oldstable distribution (buster), this problem has been fixed in version 1:4.3-12+deb10u1. For the stable distribution (bullseye), this problem has been fixed in version 1:4.4-2+deb11u1. We recommend that you upgrade your squashfs-tools packages.
Common Vulnerabilities and Exposures (CVE)
Know your vulnerabilities for free. Start using Mageni today.
Mageni can help you to find, assess and manage your vulnerabilities.Get Started for Free