xar: Unsafe Extraction — GLSA 202405-19

A vulnerability has been discovered in xar, which can lead to privilege escalation.

Affected packages

app-arch/xar on all architectures
Affected versions < 1.8.0.0.487.100.1
Unaffected versions >= 1.8.0.0.487.100.1

Background

xar provides an easily extensible archive format.

Description

A vulnerability has been discovered in xar. Please review the CVE identifier referenced below for details.

Impact

xar allows for a forward-slash separated path to be specified in the file name property, e.g. <name>x/foo</name> – as long as it doesn’t traverse upwards, and the path exists within the current directory. This means an attacker can create a .xar file which contains both a directory symlink, and a file with a name property which points into the extracted symlink directory. By abusing symlink directories in this manner, an attacker can write arbitrary files to any directory on the filesystem – providing the user has permissions to write to it.

Workaround

There is no known workaround at this time.

Resolution

All xar users should upgrade to the latest version:

 # emerge --sync
 # emerge --ask --oneshot --verbose ">=app-arch/xar-1.8.0.0.487.100.1"
 

References

Release date
May 07, 2024

Latest revision
May 07, 2024: 1

Severity
normal

Exploitable
remote

Bugzilla entries