Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2015-0857

Опубликовано: 06 мая 2016
Источник: debian
EPSS Низкий

Описание

Cool Projects TarDiff allows remote attackers to execute arbitrary commands via shell metacharacters in the name of a (1) tar file or (2) file within a tar file.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
tardifffixed0.1-5package

Примечания

  • https://anonscm.debian.org/cgit/collab-maint/tardiff.git/commit/?id=9bd6a07bc204472ac27242cea16f89943b43003a

  • Assignment is done for injection through file names and tar file name itself

  • First part was addressed in 0.1-3 but does not contain the fix for the tar

  • file name itself.

  • https://anonscm.debian.org/cgit/collab-maint/tardiff.git/commit/?id=a18e8df51511df276e61dbccdbe1714fc53af965

EPSS

Процентиль: 92%
0.05391
Низкий

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 10 лет назад

Cool Projects TarDiff allows remote attackers to execute arbitrary commands via shell metacharacters in the name of a (1) tar file or (2) file within a tar file.

CVSS3: 9.8
nvd
больше 10 лет назад

Cool Projects TarDiff allows remote attackers to execute arbitrary commands via shell metacharacters in the name of a (1) tar file or (2) file within a tar file.

CVSS3: 9.8
github
больше 4 лет назад

Cool Projects TarDiff allows remote attackers to execute arbitrary commands via shell metacharacters in the name of a (1) tar file or (2) file within a tar file.

EPSS

Процентиль: 92%
0.05391
Низкий
Уязвимость CVE-2015-0857