CVE-2023-52138: Path traversal via crafted cpio archives in Engrampa archivers

Published Feb 5, 2024
·
Updated

Engrampa is an archive manager for the MATE environment. Engrampa is found to be vulnerable to a Path Traversal vulnerability that can be leveraged to achieve full Remote Command Execution (RCE) on the target. While handling CPIO archives, the Engrampa Archive manager follows symlink, cpio by default will follow stored symlinks while extracting and the Archiver will not check the symlink location, which leads to arbitrary file writes to unintended locations. When the victim extracts the archive, the attacker can craft a malicious cpio or ISO archive to achieve RCE on the target system. This vulnerability was fixed in commit 63d5dfa.

Affected Software

2 affected componentsFixes available
Mate-desktop Engrampa<1.26.2
debian/engrampa
1.24.1-1+deb11u11.26.0-1+deb12u21.26.2-51.28.2-1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade debian/engrampa to a version that resolves this vulnerability.

    Fixed in 1.24.1-1+deb11u1Fixed in 1.26.0-1+deb12u2Fixed in 1.26.2-5Fixed in 1.28.2-1
  2. Upgrade

    Upgrade Engrampa to a version that resolves this vulnerability.

    Patch commit 63d5dfa
  3. Compensating control

    Apply a workaround/mitigation that prevents unsafe extraction of crafted CPIO/ISO archives that can trigger path traversal and RCE (e.g., block or quarantine untrusted archives from being extracted).

Event History

Feb 5, 2024
CVE Published
via MITRE·02:51 PM
Data Sourced
via MITRE·02:51 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Aug 18, 2026
Data Sourced
via Ubuntu·06:17 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·06:19 PM
DescriptionAffected Software
Data Sourced
via Launchpad·06:19 PM
Description

Frequently Asked Questions

1

What is the severity of CVE-2023-52138?

CVE-2023-52138 is considered a high severity vulnerability due to its potential for full Remote Command Execution.

2

How do I fix CVE-2023-52138?

To mitigate the risks associated with CVE-2023-52138, it is recommended to upgrade Engrampa to version 1.26.2 or later.

3

What type of vulnerability is CVE-2023-52138?

CVE-2023-52138 is classified as a Path Traversal vulnerability within the Engrampa archive manager.

4

Which software versions are affected by CVE-2023-52138?

Engrampa versions prior to 1.26.2 are affected by CVE-2023-52138.

5

Can CVE-2023-52138 be exploited remotely?

Yes, CVE-2023-52138 can be exploited to achieve Remote Command Execution, allowing attackers to run commands on the target system.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203