Vulnerabilities > Squashfs Tools Project

DATE CVE VULNERABILITY TITLE RISK
2021-09-14 CVE-2021-41072 Link Following vulnerability in multiple products
squashfs_opendir in unsquash-2.c in Squashfs-Tools 4.5 allows Directory Traversal, a different vulnerability than CVE-2021-40153.
network
low complexity
squashfs-tools-project debian CWE-59
8.1
2021-08-27 CVE-2021-40153 Path Traversal vulnerability in multiple products
squashfs_opendir in unsquash-1.c in Squashfs-Tools 4.5 stores the filename in the directory entry; this is then used by unsquashfs to create the new file during the unsquash.
8.1