• Latest
  • Trending
  • All
  • News
Critical Security Vulnerability Resolved in Binwalk, a Popular Infosec Tool

Critical Security Vulnerability Resolved in Binwalk, a Popular Infosec Tool

August 9, 2023
Preparing for Quantum-Powered Attacks: A Guide for Businesses

Preparing for Quantum-Powered Attacks: A Guide for Businesses

October 2, 2023
The Impending Threat of 'Steal Now, Crack Later' Quantum Computing

The Impending Threat of ‘Steal Now, Crack Later’ Quantum Computing

September 25, 2023
The Dominance of Email as the Primary Attack Vector

The Dominance of Email as the Primary Attack Vector

September 18, 2023
Devastating Ransomware Attack Paralyzes Danish Cloud Provider

Devastating Ransomware Attack Paralyzes Danish Cloud Provider

September 11, 2023
The Future Landscape of Ransomware Business Models: Examining Realistic Scenarios and Emerging Threats

The Future Landscape of Ransomware Business Models: Examining Realistic Scenarios and Emerging Threats

September 4, 2023
Understanding the GoAnywhere Data Breach and its Implications

Understanding the GoAnywhere Data Breach and its Implications

August 24, 2023
Safeguarding Your Identity: A Comprehensive Guide to Detecting Identity Theft

Safeguarding Your Identity: A Comprehensive Guide to Detecting Identity Theft

August 23, 2023
Identity Theft: Steps to Take in Case of a Breach

Identity Theft: Steps to Take in Case of a Breach

August 22, 2023
Enhancing Organizational Security Posture through Encryption: Key Tips

Enhancing Organizational Security Posture through Encryption: Key Tips

August 22, 2023

Understanding the Potential Threat of ‘Steal Now, Crack Later’ Attacks in Quantum Computing

August 21, 2023
Business Email Compromise Attack: A Costly Threat That Surpasses Ransomware Losses

Business Email Compromise Attack: A Costly Threat That Surpasses Ransomware Losses

August 21, 2023
The Challenges of Patching Vulnerabilities and the Importance of Prioritization

The Challenges of Patching Vulnerabilities and the Importance of Prioritization

August 20, 2023
  • About
  • Advertise
  • Privacy & Policy
  • Contact
26 °c
Ashburn
28 ° Thu
26 ° Fri
24 ° Sat
24 ° Sun
24 ° Mon
24 ° Tue
REPORT NEW Vulnerability
Tuesday, October 3, 2023
No Result
View All Result
  • Login
  • Register
Innocent Michael
  • Home
  • Solutions
  • Our Lab
    • Threat Scanner
    • Virus
    • Malware
    • Spyware
  • News
  • Products
    • Domains – Search, Register & Transfer
      • Overview
      • Register Domain
      • Transfer domain
      • Domain Renewal
      • My Domains
    • AntiVirus Protection Plan
    • Website Design Assist
    • Professional Streaming Studio
    • Legal Office Management Tool
    • Auto Attendant – Virtual Business Phone Numbers & Phone System
  • Businesses
  • Information
  • Company
  • Legal
Innocent Michael
No Result
View All Result
Home Malware

Critical Security Vulnerability Resolved in Binwalk, a Popular Infosec Tool

Cyber Intelligence by Cyber Intelligence
2 months ago
in Malware
250 5
A A
0
Critical Security Vulnerability Resolved in Binwalk, a Popular Infosec Tool
498
SHARES
1.4k
VIEWS
Share on FacebookShare on Twitter

A serious security flaw in Binwalk, a widely used security analysis tool for Linux, has been patched to address a path traversal vulnerability that could lead to remote code execution (RCE). Binwalk is a command-line tool commonly employed in firmware analysis, reverse engineering, and firmware image extraction.

According to a security advisory published by Quentin Kaiser of ONEKEY Research Lab, the path traversal vulnerability only affects users who open a “malicious file with binwalk using extract mode (-e option).” This requires user interaction. The vulnerability is categorized as CVE-2022-4510 and is considered to have high severity (CVSS 7.8).

Related articles

Malware Exposes Over 100K Hacking Forum Accounts, Researchers Reveal

Malware Exposes Over 100K Hacking Forum Accounts, Researchers Reveal

2 months ago
1.4k
Knight Ransomware Targets Users with Fake TripAdvisor Complaints in Ongoing Spam Campaign

Knight Ransomware Targets Users with Fake TripAdvisor Complaints in Ongoing Spam Campaign

2 months ago
1.4k

The root cause of the vulnerability dates back to 2017 when the Professional File System (PFS) extractor plugin was integrated with binwalk. Although the integration aimed to mitigate the path traversal risk using ‘os.path.join’, the attempt failed. Consequently, Kaiser discovered that six years later, a valid PFS filesystem with filenames containing the “../” traversal sequence could trigger binwalk to write files outside of the extraction directory.

PFS is a less common filesystem format found in some embedded devices. Kaiser deliberately targeted binwalk’s plugin system to achieve “environment agnostic” execution of remote code. By exploiting the path traversal vulnerability and crafting a valid plugin, binwalk can be forced to execute the malicious file while scanning it. Additionally, the PFS extractor automatically creates required directories if they do not exist, minimizing the system requirements.

The vulnerable versions of binwalk range from 2.1.2b to 2.3.3, inclusive. The team at Refirm Labs, owned by Microsoft, addressed the vulnerability by releasing binwalk version 2.3.4 on February 2, 2023. ONEKEY Research Lab had initially contacted the maintainers of binwalk in October 2022 and provided a suggested patch.

Further research by Kaiser revealed similar medium severity vulnerabilities, denoted as CVEs, in other filesystem extractors including ubi_reader, Jefferson, and yaffshiv. Yaffshiv, the extractor used by binwalk by default, can potentially expose fully updated instances of binwalk to the same exploit chain, but with YAFFS as the attack vector instead of PFS.

Kaiser highlighted the need to be cautious and aware of possible vulnerabilities in security tools, particularly in forensic analysis and reverse engineering. It underlines the importance of sandboxing analysis environments to limit the impact of such vulnerabilities, especially considering the increasing use of automated extraction and analysis tools relying on binwalk, such as FACT, ofrak, and EMBA.

Kaiser also hinted at the possibility of a similar vulnerability affecting the ‘D-Link RomFS’ plugin, suggesting potential future research in that area. The Daily Swig has reached out to Refirm Labs for comment, and any response will be communicated in an updated article.

Share199Tweet124
Cyber Intelligence

Cyber Intelligence

Subscribe
Connect with
Login
I allow to create an account
When you login first time using a Social Login button, we collect your account public profile information shared by Social Login provider, based on your privacy settings. We also get your email address to automatically create an account for you in our website. Once your account is created, you'll be logged-in to this account.
DisagreeAgree
Notify of
guest
I allow to create an account
When you login first time using a Social Login button, we collect your account public profile information shared by Social Login provider, based on your privacy settings. We also get your email address to automatically create an account for you in our website. Once your account is created, you'll be logged-in to this account.
DisagreeAgree
guest
0 Comments
Inline Feedbacks
View all comments
Innocent Michael

Copyright © 2023 Inncent Michael.

Navigate Site

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Follow Us

No Result
View All Result
  • Home
  • Solutions
  • Our Lab
    • Threat Scanner
    • Virus
    • Malware
    • Spyware
  • News
  • Products
    • Domains – Search, Register & Transfer
      • Overview
      • Register Domain
      • Transfer domain
      • Domain Renewal
      • My Domains
    • AntiVirus Protection Plan
    • Website Design Assist
    • Professional Streaming Studio
    • Legal Office Management Tool
    • Auto Attendant – Virtual Business Phone Numbers & Phone System
  • Businesses
  • Information
  • Company
  • Legal
  • Login
  • Sign Up
REPORT NEW Vulnerability

Welcome Back!

Sign In with Google
OR

Login to your account below

Forgotten Password? Sign Up

Create New Account!

Sign Up with Google
OR

Fill the forms below to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

wpDiscuz
0
0
Would love your thoughts, please comment.x
()
x
| Reply
Update Contents