Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2014-9447

Опубликовано: 02 янв. 2015
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 6.4

Описание

Directory traversal vulnerability in the read_long_names function in libelf/elf_begin.c in elfutils 0.152 and 0.161 allows remote attackers to write to arbitrary files to the root directory via a / (slash) in a crafted archive, as demonstrated using the ar program.

РелизСтатусПримечание
devel

released

0.160-0ubuntu3
esm-infra-legacy/trusty

released

0.158-0ubuntu5.2
lucid

released

0.143-1ubuntu0.1
precise

released

0.152-1ubuntu3.1
trusty

released

0.158-0ubuntu5.2
trusty/esm

released

0.158-0ubuntu5.2
upstream

released

0.159-4.1
utopic

released

0.160-0ubuntu2.1

Показывать по

EPSS

Процентиль: 87%
0.03517
Низкий

6.4 Medium

CVSS2

Связанные уязвимости

redhat
около 11 лет назад

Directory traversal vulnerability in the read_long_names function in libelf/elf_begin.c in elfutils 0.152 and 0.161 allows remote attackers to write to arbitrary files to the root directory via a / (slash) in a crafted archive, as demonstrated using the ar program.

nvd
около 11 лет назад

Directory traversal vulnerability in the read_long_names function in libelf/elf_begin.c in elfutils 0.152 and 0.161 allows remote attackers to write to arbitrary files to the root directory via a / (slash) in a crafted archive, as demonstrated using the ar program.

debian
около 11 лет назад

Directory traversal vulnerability in the read_long_names function in l ...

suse-cvrf
почти 11 лет назад

Security update for elfutils

suse-cvrf
около 11 лет назад

Security update for elfutils

EPSS

Процентиль: 87%
0.03517
Низкий

6.4 Medium

CVSS2