ALT-PU-2016-1000-1
Closed vulnerabilities
Published: 2015-01-21
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2015-1038
p7zip 9.20.1 allows remote attackers to write to arbitrary files via a symlink attack in an archive.
Severity: MEDIUM (5.8)
References:
- FEDORA-2015-fadaa9953e
- FEDORA-2015-fadaa9953e
- FEDORA-2015-d5cc306730
- FEDORA-2015-d5cc306730
- openSUSE-SU-2015:1162
- openSUSE-SU-2015:1162
- DSA-3289
- DSA-3289
- [oss-security] 20150111 Re: CVE request for directory traversal flaw in p7zip
- [oss-security] 20150111 Re: CVE request for directory traversal flaw in p7zip
- http://www.oracle.com/technetwork/topics/security/bulletinjul2015-2511963.html
- http://www.oracle.com/technetwork/topics/security/bulletinjul2015-2511963.html
- 71890
- 71890
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=774660
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=774660
- https://bugzilla.redhat.com/show_bug.cgi?id=1179505
- https://bugzilla.redhat.com/show_bug.cgi?id=1179505
- p7zip-cve20151038-symlink(99970)
- p7zip-cve20151038-symlink(99970)