PT-2015-4712 · Gnome+1 · Gcab+1
Stephen Kitt
·
Published
2015-01-09
·
Updated
2018-10-30
·
CVE-2015-0552
CVSS v2.0
6.4
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
gcab version 0.4
Description
A directory traversal issue exists in the gcab folder extract function, allowing remote attackers to write to arbitrary files via a crafted path in a CAB file. This can be achieved by using a specially crafted path, such as "tmpmoo".
Recommendations
For gcab version 0.4, consider restricting access to the gcab folder extract function until a patch is available, or avoid using this function with untrusted CAB files to minimize the risk of exploitation.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Gcab