CVE-2022-4510

NameCVE-2022-4510
Description A path traversal vulnerability was identified in ReFirm Labs binwalk from version 2.1.2b through 2.3.3 included. By crafting a malicious PFS filesystem file, an attacker can get binwalk's PFS extractor to extract files at arbitrary locations when binwalk is run in extraction mode (-e option). Remote code execution can be achieved by building a PFS filesystem that, upon extraction, would extract a malicious binwalk module into the folder .config/binwalk/plugins. This vulnerability is associated with program files src/binwalk/plugins/unpfs.py. This issue affects binwalk from 2.1.2b through 2.3.3 included.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDLA-3339-1

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
binwalk (PTS)jessie2.0.1+dfsg-1vulnerable
stretch2.1.1-16vulnerable
buster (security), buster, buster (lts)2.1.2~git20180830+dfsg1-1+deb10u1fixed
bullseye2.3.1+dfsg1-1vulnerable
bookworm2.3.4+dfsg1-1fixed
sid, trixie2.4.3+dfsg1-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
binwalksourcejessie(unfixed)end-of-life
binwalksourcestretch(unfixed)end-of-life
binwalksourcebuster2.1.2~git20180830+dfsg1-1+deb10u1DLA-3339-1
binwalksource(unstable)2.3.4+dfsg1-1

Notes

[bullseye] - binwalk <no-dsa> (Minor issue)
https://github.com/ReFirmLabs/binwalk/pull/617
https://github.com/ReFirmLabs/binwalk/commit/696fe34ed680ffd951bfeca737feb4a0b98dde5c (v2.3.4)

Search for package or bug name: Reporting problems