Deepin-Compressor is the default archive manager of Deepin Linux OS. Prior to 5.12.21, there's a path traversal vulnerability in deepin-compressor that can be exploited to achieve Remote Command Execution on the target system upon opening crafted archives. Users are advised to update to version 5.12.21 which addresses the issue. There are no known workarounds for this vulnerability.
The vulnerability results from improper verification of file paths during archive extraction (CWE-22, CWE-23, CWE-26). An attacker can prepare a specially crafted archive containing files with paths extending beyond the target extraction directory. When the victim opens such an archive, the application extracts files to unintended locations in the file system, which can lead to execution of malicious code on the target system.
Successful exploitation of the vulnerability allows an attacker to remotely execute arbitrary commands (RCE) on the victim's system with the privileges of the user running the application. This can lead to compromise of confidentiality and integrity of system data.
Deepin-Compressor should be updated to version 5.12.21, which removes the described vulnerability. The vendor does not provide any workarounds for this vulnerability — updating is the only recommended action.
Deepin-Compressor in versions earlier than 5.12.21 on Deepin Linux OS system.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:NDeepin Compressor
APPDeepin< 5.12.21
Related vulnerabilities
RCE w Deepin Reader poprzez path traversal w plikach DOCX
deepin-clone before 1.1.3 uses a predictable path /tmp/.deepin-clone/mount/<block-dev-basename> in the Helper:...
dde-daemon, the daemon process of DDE (Deepin Desktop Environment) 15.0 through 15.3, runs with root privilege...
In GUI mode, deepin-clone before 1.1.3 creates a log file at the fixed path /tmp/.deepin-clone.log as root, an...
deepin-clone before 1.1.3 uses a fixed path /tmp/repo.iso in the BootDoctor::fix() function to download an ISO...