Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x4gq-xcr8-xwp7

Опубликовано: 29 фев. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 4.9

Описание

Debian's cpio contains a path traversal vulnerability. This issue was introduced by reverting CVE-2015-1197 patches which had caused a regression in --no-absolute-filenames. Upstream has since provided a proper fix to --no-absolute-filenames.

Debian's cpio contains a path traversal vulnerability. This issue was introduced by reverting CVE-2015-1197 patches which had caused a regression in --no-absolute-filenames. Upstream has since provided a proper fix to --no-absolute-filenames.

EPSS

Процентиль: 19%
0.00061
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 4.9
ubuntu
почти 2 года назад

Debian's cpio contains a path traversal vulnerability. This issue was introduced by reverting CVE-2015-1197 patches which had caused a regression in --no-absolute-filenames. Upstream has since provided a proper fix to --no-absolute-filenames.

CVSS3: 5.5
redhat
около 2 лет назад

Debian's cpio contains a path traversal vulnerability. This issue was introduced by reverting CVE-2015-1197 patches which had caused a regression in --no-absolute-filenames. Upstream has since provided a proper fix to --no-absolute-filenames.

CVSS3: 4.9
nvd
почти 2 года назад

Debian's cpio contains a path traversal vulnerability. This issue was introduced by reverting CVE-2015-1197 patches which had caused a regression in --no-absolute-filenames. Upstream has since provided a proper fix to --no-absolute-filenames.

msrc
5 месяцев назад

Debian's cpio contains a path traversal vulnerability. This issue was introduced by reverting CVE-2015-1197 patches which had caused a regression in --no-absolute-filenames. Upstream has since provided a proper fix to --no-absolute-filenames.

CVSS3: 4.9
debian
почти 2 года назад

Debian's cpio contains a path traversal vulnerability. This issue was ...

EPSS

Процентиль: 19%
0.00061
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-22