Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2014-9447

Опубликовано: 02 янв. 2015
Источник: debian

Описание

Directory traversal vulnerability in the read_long_names function in libelf/elf_begin.c in elfutils 0.152 and 0.161 allows remote attackers to write to arbitrary files to the root directory via a / (slash) in a crafted archive, as demonstrated using the ar program.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
elfutilsfixed0.159-4.1package
elfutilsno-dsawheezypackage
elfutilsno-dsasqueezepackage

Примечания

  • https://git.fedorahosted.org/cgit/elfutils.git/commit/?id=147018e729e7c22eeabf15b82d26e4bf68a0d18e

Связанные уязвимости

ubuntu
около 11 лет назад

Directory traversal vulnerability in the read_long_names function in libelf/elf_begin.c in elfutils 0.152 and 0.161 allows remote attackers to write to arbitrary files to the root directory via a / (slash) in a crafted archive, as demonstrated using the ar program.

redhat
около 11 лет назад

Directory traversal vulnerability in the read_long_names function in libelf/elf_begin.c in elfutils 0.152 and 0.161 allows remote attackers to write to arbitrary files to the root directory via a / (slash) in a crafted archive, as demonstrated using the ar program.

nvd
около 11 лет назад

Directory traversal vulnerability in the read_long_names function in libelf/elf_begin.c in elfutils 0.152 and 0.161 allows remote attackers to write to arbitrary files to the root directory via a / (slash) in a crafted archive, as demonstrated using the ar program.

suse-cvrf
почти 11 лет назад

Security update for elfutils

suse-cvrf
около 11 лет назад

Security update for elfutils