Vulnerability Description
Cool Projects TarDiff allows remote attackers to execute arbitrary commands via shell metacharacters in the name of a (1) tar file or (2) file within a tar file.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Tardiff Project | Tardiff | - |
| Debian | Debian Linux | 8.0 |
Related Weaknesses (CWE)
References
- http://www.debian.org/security/2016/dsa-3562
- https://anonscm.debian.org/cgit/collab-maint/tardiff.git/commit/?id=9bd6a07bc204
- https://anonscm.debian.org/cgit/collab-maint/tardiff.git/commit/?id=a18e8df51511
- http://www.debian.org/security/2016/dsa-3562
- https://anonscm.debian.org/cgit/collab-maint/tardiff.git/commit/?id=9bd6a07bc204
- https://anonscm.debian.org/cgit/collab-maint/tardiff.git/commit/?id=a18e8df51511
FAQ
What is CVE-2015-0857?
CVE-2015-0857 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Cool Projects TarDiff allows remote attackers to execute arbitrary commands via shell metacharacters in the name of a (1) tar file or (2) file within a tar file.
How severe is CVE-2015-0857?
CVE-2015-0857 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2015-0857?
Check the references section above for vendor advisories and patch information. Affected products include: Tardiff Project Tardiff, Debian Debian Linux.