Description
Specially-crafted command line arguments can lead to arbitrary file deletion. The handle_delete function does not attempt to sanitize or otherwise validate the contents of the [file] parameter (passed to the function as argv[1]), allowing an authenticated attacker to supply directory traversal primitives and delete semi-arbitrary files.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-9079 | Specially-crafted command line arguments can lead to arbitrary file deletion. The handle_delete function does not attempt to sanitize or otherwise validate the contents of the [file] parameter (passed to the function as argv[1]), allowing an authenticated attacker to supply directory traversal primitives and delete semi-arbitrary files. |
References
History
No history.
Status: PUBLISHED
Assigner: talos
Published:
Updated: 2024-08-03T18:30:22.889Z
Reserved: 2021-01-04T00:00:00.000Z
Link: CVE-2021-21908
No data.
Status : Modified
Published: 2021-12-22T19:15:09.917
Modified: 2024-11-21T05:49:13.340
Link: CVE-2021-21908
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD