Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2015-2060

Опубликовано: 29 нояб. 2019
Источник: debian

Описание

cabextract before 1.6 does not properly check for leading slashes when extracting files, which allows remote attackers to conduct absolute directory traversal attacks via a malformed UTF-8 character that is changed to a UTF-8 encoded slash.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
cabextractfixed1.6-1package
cabextractno-dsajessiepackage
cabextractno-dsawheezypackage
cabextractno-dsasqueezepackage

Примечания

  • https://www.openwall.com/lists/oss-security/2015/02/18/3

  • Upstream commit: http://sourceforge.net/p/libmspack/code/217

  • CVE assigned for issue were path traversal occurs because the unpatched

  • code does neither of the following: 1) checking for slashes after decoding

  • 2) checking for ordinary slashes before decoding and prohibiting overlong

  • encodings

Связанные уязвимости

CVSS3: 5.3
ubuntu
около 6 лет назад

cabextract before 1.6 does not properly check for leading slashes when extracting files, which allows remote attackers to conduct absolute directory traversal attacks via a malformed UTF-8 character that is changed to a UTF-8 encoded slash.

CVSS3: 5.3
nvd
около 6 лет назад

cabextract before 1.6 does not properly check for leading slashes when extracting files, which allows remote attackers to conduct absolute directory traversal attacks via a malformed UTF-8 character that is changed to a UTF-8 encoded slash.

github
больше 3 лет назад

cabextract before 1.6 does not properly check for leading slashes when extracting files, which allows remote attackers to conduct absolute directory traversal attacks via a malformed UTF-8 character that is changed to a UTF-8 encoded slash.