MEDIUM5.3
Audit before 2.4.4 in Linux does not sanitize escape characters in filenames.
CVSS 2.0MEDIUM 5.0
CVSS:2.0/AV:N/AC:L/Au:N/C:N/I:P/A:NCVSS 3.xMEDIUM 5.3
CVSS:3.x/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:NReferences
- http://www.openwall.com/lists/oss-security/2015/08/13/9
- http://www.securityfocus.com/bid/76840
- https://bugzilla.redhat.com/show_bug.cgi?id=1251621
- https://people.redhat.com/sgrubb/audit/ChangeLog
- http://www.openwall.com/lists/oss-security/2015/08/13/9
- http://www.securityfocus.com/bid/76840
- https://bugzilla.redhat.com/show_bug.cgi?id=1251621
- https://people.redhat.com/sgrubb/audit/ChangeLog