Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-9447

Опубликовано: 27 дек. 2014
Источник: redhat
CVSS2: 2.1

Описание

Directory traversal vulnerability in the read_long_names function in libelf/elf_begin.c in elfutils 0.152 and 0.161 allows remote attackers to write to arbitrary files to the root directory via a / (slash) in a crafted archive, as demonstrated using the ar program.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Developer Toolset 2.1devtoolset-2-elfutilsWill not fix
Red Hat Enterprise Linux 5elfutilsWill not fix
Red Hat Enterprise Linux 6elfutilsFixedRHEA-2015:130220.07.2015
Red Hat Enterprise Linux 7elfutilsFixedRHEA-2015:212619.11.2015

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-73
https://bugzilla.redhat.com/show_bug.cgi?id=1178888elfutils: directory traversal in read_long_names()

2.1 Low

CVSS2

Связанные уязвимости

ubuntu
около 11 лет назад

Directory traversal vulnerability in the read_long_names function in libelf/elf_begin.c in elfutils 0.152 and 0.161 allows remote attackers to write to arbitrary files to the root directory via a / (slash) in a crafted archive, as demonstrated using the ar program.

nvd
около 11 лет назад

Directory traversal vulnerability in the read_long_names function in libelf/elf_begin.c in elfutils 0.152 and 0.161 allows remote attackers to write to arbitrary files to the root directory via a / (slash) in a crafted archive, as demonstrated using the ar program.

debian
около 11 лет назад

Directory traversal vulnerability in the read_long_names function in l ...

suse-cvrf
почти 11 лет назад

Security update for elfutils

suse-cvrf
около 11 лет назад

Security update for elfutils

2.1 Low

CVSS2