Логотип exploitDog
bind:CVE-2015-8768
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2015-8768

Количество 3

Количество 3

ubuntu логотип

CVE-2015-8768

почти 9 лет назад

click/install.py in click does not require files in package filesystem tarballs to start with ./ (dot slash), which allows remote attackers to install an alternate security policy and gain privileges via a crafted package, as demonstrated by the test.mmrow app for Ubuntu phone.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2015-8768

почти 9 лет назад

click/install.py in click does not require files in package filesystem tarballs to start with ./ (dot slash), which allows remote attackers to install an alternate security policy and gain privileges via a crafted package, as demonstrated by the test.mmrow app for Ubuntu phone.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-fgm2-j3wp-hrw5

больше 3 лет назад

click/install.py in click does not require files in package filesystem tarballs to start with ./ (dot slash), which allows remote attackers to install an alternate security policy and gain privileges via a crafted package, as demonstrated by the test.mmrow app for Ubuntu phone.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2015-8768

click/install.py in click does not require files in package filesystem tarballs to start with ./ (dot slash), which allows remote attackers to install an alternate security policy and gain privileges via a crafted package, as demonstrated by the test.mmrow app for Ubuntu phone.

CVSS3: 9.8
2%
Низкий
почти 9 лет назад
nvd логотип
CVE-2015-8768

click/install.py in click does not require files in package filesystem tarballs to start with ./ (dot slash), which allows remote attackers to install an alternate security policy and gain privileges via a crafted package, as demonstrated by the test.mmrow app for Ubuntu phone.

CVSS3: 9.8
2%
Низкий
почти 9 лет назад
github логотип
GHSA-fgm2-j3wp-hrw5

click/install.py in click does not require files in package filesystem tarballs to start with ./ (dot slash), which allows remote attackers to install an alternate security policy and gain privileges via a crafted package, as demonstrated by the test.mmrow app for Ubuntu phone.

CVSS3: 9.8
2%
Низкий
больше 3 лет назад

Уязвимостей на страницу