ALT-PU-2022-6811-1
Package arj updated to version 3.10.22-alt9 for branch sisyphus_mipsel.
Closed vulnerabilities
Published: 2015-04-08
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2015-0557
Open-source ARJ archiver 3.10.22 does not properly remove leading slashes from paths, which allows remote attackers to conduct absolute path traversal attacks and write to arbitrary files via multiple leading slashes in a path in an ARJ archive.
Severity: MEDIUM (5.8)
References:
- FEDORA-2015-5603
- FEDORA-2015-5603
- FEDORA-2015-5546
- FEDORA-2015-5546
- FEDORA-2015-5524
- FEDORA-2015-5524
- DSA-3213
- DSA-3213
- MDVSA-2015:201
- MDVSA-2015:201
- [oss-security] 20150103 CVE Request: arj: symlink directory traversal and directory traversal via //multiple/leading/slash
- [oss-security] 20150103 CVE Request: arj: symlink directory traversal and directory traversal via //multiple/leading/slash
- [oss-security] 20150105 Re: CVE Request: arj: symlink directory traversal and directory traversal via //multiple/leading/slash
- [oss-security] 20150105 Re: CVE Request: arj: symlink directory traversal and directory traversal via //multiple/leading/slash
- 71895
- 71895
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=774435
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=774435
- GLSA-201612-15
- GLSA-201612-15
Closed bugs
Зависает при создании архивов