Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2015-0857

Опубликовано: 06 мая 2016
Источник: debian

Описание

Cool Projects TarDiff allows remote attackers to execute arbitrary commands via shell metacharacters in the name of a (1) tar file or (2) file within a tar file.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
tardifffixed0.1-5package

Примечания

  • https://anonscm.debian.org/cgit/collab-maint/tardiff.git/commit/?id=9bd6a07bc204472ac27242cea16f89943b43003a

  • Assignment is done for injection through file names and tar file name itself

  • First part was addressed in 0.1-3 but does not contain the fix for the tar

  • file name itself.

  • https://anonscm.debian.org/cgit/collab-maint/tardiff.git/commit/?id=a18e8df51511df276e61dbccdbe1714fc53af965

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 10 лет назад

Cool Projects TarDiff allows remote attackers to execute arbitrary commands via shell metacharacters in the name of a (1) tar file or (2) file within a tar file.

CVSS3: 9.8
nvd
почти 10 лет назад

Cool Projects TarDiff allows remote attackers to execute arbitrary commands via shell metacharacters in the name of a (1) tar file or (2) file within a tar file.

CVSS3: 9.8
github
больше 3 лет назад

Cool Projects TarDiff allows remote attackers to execute arbitrary commands via shell metacharacters in the name of a (1) tar file or (2) file within a tar file.