Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2022-4515

Опубликовано: 20 дек. 2022
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 7.8

Описание

A flaw was found in Exuberant Ctags in the way it handles the "-o" option. This option specifies the tag filename. A crafted tag filename specified in the command line or in the configuration file results in arbitrary command execution because the externalSortTags() in sort.c calls the system(3) function in an unsafe way.

РелизСтатусПримечание
bionic

released

1:5.9~svn20110310-11ubuntu0.1
devel

not-affected

1:5.9~svn20110310-18
esm-infra-legacy/xenial

released

1:5.9~svn20110310-11ubuntu0.1~esm1
esm-infra/bionic

released

1:5.9~svn20110310-11ubuntu0.1
esm-infra/focal

released

1:5.9~svn20110310-12ubuntu0.1
esm-infra/xenial

released

1:5.9~svn20110310-11ubuntu0.1~esm1
focal

released

1:5.9~svn20110310-12ubuntu0.1
jammy

released

1:5.9~svn20110310-16ubuntu0.22.04.1
kinetic

released

1:5.9~svn20110310-16ubuntu0.22.10.1
trusty

ignored

end of standard support

Показывать по

EPSS

Процентиль: 44%
0.00577
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
redhat
больше 3 лет назад

A flaw was found in Exuberant Ctags in the way it handles the "-o" option. This option specifies the tag filename. A crafted tag filename specified in the command line or in the configuration file results in arbitrary command execution because the externalSortTags() in sort.c calls the system(3) function in an unsafe way.

CVSS3: 7.8
nvd
больше 3 лет назад

A flaw was found in Exuberant Ctags in the way it handles the "-o" option. This option specifies the tag filename. A crafted tag filename specified in the command line or in the configuration file results in arbitrary command execution because the externalSortTags() in sort.c calls the system(3) function in an unsafe way.

CVSS3: 7.8
msrc
больше 3 лет назад

A flaw was found in Exuberant Ctags in the way it handles the "-o" option. This option specifies the tag filename. A crafted tag filename specified in the command line or in the configuration file results in arbitrary command execution because the externalSortTags() in sort.c calls the system(3) function in an unsafe way.

CVSS3: 7.8
debian
больше 3 лет назад

A flaw was found in Exuberant Ctags in the way it handles the "-o" opt ...

suse-cvrf
больше 3 лет назад

Security update for ctags

EPSS

Процентиль: 44%
0.00577
Низкий

7.8 High

CVSS3