Vulnerability Description
cabextract before 1.6 does not properly check for leading slashes when extracting files, which allows remote attackers to conduct absolute directory traversal attacks via a malformed UTF-8 character that is changed to a UTF-8 encoded slash.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cabextract Project | Cabextract | < 1.6 |
| Linux | Linux Kernel | - |
Related Weaknesses (CWE)
References
- http://lists.fedoraproject.org/pipermail/package-announce/2015-March/151145.htmlIssue TrackingPatchThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2015-March/151147.htmlIssue TrackingPatchThird Party Advisory
- http://www.cabextract.org.uk/Vendor Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2015:064Broken Link
- http://www.openwall.com/lists/oss-security/2015/02/18/3ExploitMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2015/02/23/16Mailing ListMitigationThird Party Advisory
- http://www.openwall.com/lists/oss-security/2015/02/23/24Mailing ListMitigationThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2015-March/151145.htmlIssue TrackingPatchThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2015-March/151147.htmlIssue TrackingPatchThird Party Advisory
- http://www.cabextract.org.uk/Vendor Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2015:064Broken Link
- http://www.openwall.com/lists/oss-security/2015/02/18/3ExploitMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2015/02/23/16Mailing ListMitigationThird Party Advisory
- http://www.openwall.com/lists/oss-security/2015/02/23/24Mailing ListMitigationThird Party Advisory
FAQ
What is CVE-2015-2060?
CVE-2015-2060 is a vulnerability with a CVSS score of 5.3 (MEDIUM). cabextract before 1.6 does not properly check for leading slashes when extracting files, which allows remote attackers to conduct absolute directory traversal attacks via a malformed UTF-8 character t...
How severe is CVE-2015-2060?
CVE-2015-2060 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2015-2060?
Check the references section above for vendor advisories and patch information. Affected products include: Cabextract Project Cabextract, Linux Linux Kernel.