FS#70714 - [impacket] [Security] directory traversal (CVE-2021-31800)
Attached to Project:
Community Packages
Opened by Jonas Witschel (diabonas) - Wednesday, 05 May 2021, 12:24 GMT
Last edited by Jonas Witschel (diabonas) - Tuesday, 20 July 2021, 19:21 GMT
Opened by Jonas Witschel (diabonas) - Wednesday, 05 May 2021, 12:24 GMT
Last edited by Jonas Witschel (diabonas) - Tuesday, 20 July 2021, 19:21 GMT
|
Details
Summary
======= The package impacket is vulnerable to directory traversal via CVE-2021-31800. Guidance ======== Applying the commit referenced below fixes the issue. The mentioned pull request also contains a second commit (https://github.com/SecureAuthCorp/impacket/commit/6688da5d97592269aae72b3a00dc1ab186c0b33d) which changes some error response codes, but that doesn't seem to be security-related and is therefore not strictly necessary to fix the issue. References ========== https://security.archlinux.org/AVG-1916 https://github.com/SecureAuthCorp/impacket/pull/1066 https://github.com/SecureAuthCorp/impacket/commit/99bd29e3995c254e2d6f6c2e3454e4271665955a |
This task depends upon
Closed by Jonas Witschel (diabonas)
Tuesday, 20 July 2021, 19:21 GMT
Reason for closing: Fixed
Additional comments about closing: impacket 0.9.23-1
Tuesday, 20 July 2021, 19:21 GMT
Reason for closing: Fixed
Additional comments about closing: impacket 0.9.23-1