CVE-2015-0552Path Traversal in Gcab

CWE-22Path Traversal7 documents6 sources
Severity
6.4MEDIUMNVD
EPSS
0.7%
top 27.13%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 15
Latest updateMay 14

Description

Directory traversal vulnerability in the gcab_folder_extract function in libgcab/gcab-folder.c in gcab 0.4 allows remote attackers to write to arbitrary files via crafted path in a CAB file, as demonstrated by "\tmp\moo."

CVSS vector

AV:N/AC:L/C:N/I:P/A:PExploitability: 10.0 | Impact: 4.9

Affected Packages3 packages

Debiangnome/gcab< 0.4-2+3
NVDgnome/gcab0.4
NVDopensuse/opensuse13.1, 13.2+1

🔴Vulnerability Details

3
GHSA
GHSA-h25c-q8jq-gr57: Directory traversal vulnerability in the gcab_folder_extract function in libgcab/gcab-folder2022-05-14
OSV
CVE-2015-0552: Directory traversal vulnerability in the gcab_folder_extract function in libgcab/gcab-folder2015-01-15
CVEList
CVE-2015-0552: Directory traversal vulnerability in the gcab_folder_extract function in libgcab/gcab-folder2015-01-15

📋Vendor Advisories

1
Debian
CVE-2015-0552: gcab - Directory traversal vulnerability in the gcab_folder_extract function in libgcab...2015

💬Community

2
Bugzilla
CVE-2015-0552 gcab: directory traversal flaw2015-01-06
Bugzilla
CVE-2015-0552 gcab: directory traversal flaw [fedora-all]2015-01-06
CVE-2015-0552 — Path Traversal in Gnome Gcab | cvebase