Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-4035

Опубликовано: 18 мая 2015
Источник: redhat
CVSS2: 4.4

Описание

scripts/xzgrep.in in xzgrep 5.2.x before 5.2.0, before 5.0.0 does not properly process file names containing semicolons, which allows remote attackers to execute arbitrary code by having a user run xzgrep on a crafted file name.

It was discovered that the xzgrep's xz helper script did not properly sanitize certain file names. A local attacker could use this flaw to inject and execute arbitrary commands by tricking a user into running the xzgrep script on a file with a specially crafted file name.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5xzWill not fix
Red Hat Enterprise Linux 6xzWill not fix
Red Hat Enterprise Linux 7xzNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-20->CWE-77
https://bugzilla.redhat.com/show_bug.cgi?id=1223341xzgrep: incorrect parsing of filenames containing a semicolon

4.4 Medium

CVSS2

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 8 лет назад

scripts/xzgrep.in in xzgrep 5.2.x before 5.2.0, before 5.0.0 does not properly process file names containing semicolons, which allows remote attackers to execute arbitrary code by having a user run xzgrep on a crafted file name.

CVSS3: 7.8
nvd
больше 8 лет назад

scripts/xzgrep.in in xzgrep 5.2.x before 5.2.0, before 5.0.0 does not properly process file names containing semicolons, which allows remote attackers to execute arbitrary code by having a user run xzgrep on a crafted file name.

CVSS3: 7.8
debian
больше 8 лет назад

scripts/xzgrep.in in xzgrep 5.2.x before 5.2.0, before 5.0.0 does not ...

CVSS3: 7.8
github
больше 3 лет назад

scripts/xzgrep.in in xzgrep 5.2.x before 5.2.0, before 5.0.0 does not properly process file names containing semicolons, which allows remote attackers to execute arbitrary code by having a user run xzgrep on a crafted file name.

4.4 Medium

CVSS2