https://seclists.org/oss-sec/2025/q2/84: [EXTERNAL] [oss-security] vulnerabilities in busybox tar and cpio tools
Published Apr 24, 2025
·Updated
Affected Software
1 affected component
Busybox Busybox
Frequently Asked Questions
1
What is CVE-2023-39810?
CVE-2023-39810 is a vulnerability found in the BusyBox tar and cpio tools that allows for path traversal attacks.
2
What is the severity of CVE-2023-39810?
The severity of CVE-2023-39810 is considered significant due to its potential to compromise file system integrity.
3
How do I fix CVE-2023-39810?
To fix CVE-2023-39810, update BusyBox to the latest version that includes the patch addressing the vulnerability.
4
What could happen if CVE-2023-39810 is exploited?
If exploited, CVE-2023-39810 could allow an attacker to overwrite arbitrary files on the system.
5
Is there a workaround for CVE-2023-39810?
A temporary workaround for CVE-2023-39810 is to restrict access to the BusyBox tar and cpio commands until the software is updated.