Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6vj6-pqrx-qcx6

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Absolute path traversal vulnerability in the handleStartDataFile function in DigiDocSAXParser.c in libdigidoc 3.6.0.0, as used in ID-software before 3.7.2 and other products, allows remote attackers to overwrite arbitrary files via a filename beginning with / (slash) or \ (backslash) in a DDOC file.

Absolute path traversal vulnerability in the handleStartDataFile function in DigiDocSAXParser.c in libdigidoc 3.6.0.0, as used in ID-software before 3.7.2 and other products, allows remote attackers to overwrite arbitrary files via a filename beginning with / (slash) or \ (backslash) in a DDOC file.

EPSS

Процентиль: 69%
0.006
Низкий

Дефекты

CWE-22

Связанные уязвимости

ubuntu
больше 12 лет назад

Absolute path traversal vulnerability in the handleStartDataFile function in DigiDocSAXParser.c in libdigidoc 3.6.0.0, as used in ID-software before 3.7.2 and other products, allows remote attackers to overwrite arbitrary files via a filename beginning with / (slash) or \ (backslash) in a DDOC file.

nvd
больше 12 лет назад

Absolute path traversal vulnerability in the handleStartDataFile function in DigiDocSAXParser.c in libdigidoc 3.6.0.0, as used in ID-software before 3.7.2 and other products, allows remote attackers to overwrite arbitrary files via a filename beginning with / (slash) or \ (backslash) in a DDOC file.

debian
больше 12 лет назад

Absolute path traversal vulnerability in the handleStartDataFile funct ...

EPSS

Процентиль: 69%
0.006
Низкий

Дефекты

CWE-22