PT-2023-4600 · Unknown+3 · Libarchive+3

·

CVE-2023-30571

·

Published

2023-05-29

·

Updated

2025-01-14

CVSS v3.1

5.3

Medium

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H
Name of the Vulnerable Software and Affected Versions Libarchive versions 3.6.2 and earlier
Description The issue is caused by a race condition with the umask() call inside archive write disk posix.c, which can lead to a permanent umask 0 setting. This can result in implicit directory creation with permissions 0777, allowing any low-privileged local user to delete and rename files inside those directories. The umask() function changes the umask of the whole process for a short period, and a race condition with another thread can cause this setting to become permanent.
Recommendations For Libarchive versions 3.6.2 and earlier, consider updating to a version later than 3.6.2 to resolve the issue. As a temporary workaround, consider restricting access to directories that may be affected by this issue to minimize the risk of exploitation. Additionally, be cautious when using the archive write disk posix.c component, as it may be vulnerable to this race condition.

Exploit

Fix

DoS

Race Condition

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2024-13156
ALT-PU-2024-13375
BDU:2023-05007
CVE-2023-30571
ECHO-5552-CE75-412D

Affected Products

Alt Linux
Debian
Libarchive
Red Os