cve/2023/CVE-2023-0592.md
2024-06-18 02:51:15 +02:00

18 lines
850 B
Markdown

### [CVE-2023-0592](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-0592)
![](https://img.shields.io/static/v1?label=Product&message=jefferson&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=%3D%200%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-22%20Improper%20Limitation%20of%20a%20Pathname%20to%20a%20Restricted%20Directory%20('Path%20Traversal')&color=brighgreen)
### Description
A path traversal vulnerability affects jefferson's JFFS2 filesystem extractor. By crafting malicious JFFS2 files, attackers could force jefferson to write outside of the extraction directory.This issue affects jefferson: before 0.4.1.
### POC
#### Reference
- https://onekey.com/blog/security-advisory-remote-command-execution-in-binwalk/
#### Github
No PoCs found on GitHub currently.