CVE-2015-1038Link Following in P7zip

CWE-59Link Following7 documents6 sources
Severity
5.8MEDIUMNVD
EPSS
3.2%
top 13.01%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 21
Latest updateMay 17

Description

p7zip 9.20.1 allows remote attackers to write to arbitrary files via a symlink attack in an archive.

CVSS vector

AV:N/AC:M/C:N/I:P/A:PExploitability: 8.6 | Impact: 4.9

Affected Packages3 packages

Debian7-zip/p7zip< 9.20.1~dfsg.1-4.2+2
NVD7-zip/p7zip9.20.1
NVDoracle/solaris10.0, 11.2+1

Also affects: Fedora 22, 23

🔴Vulnerability Details

3
GHSA
GHSA-f24r-hqqw-w96v: p7zip 92022-05-17
OSV
CVE-2015-1038: p7zip 92015-01-21
CVEList
CVE-2015-1038: p7zip 92015-01-21

📋Vendor Advisories

1
Debian
CVE-2015-1038: p7zip - p7zip 9.20.1 allows remote attackers to write to arbitrary files via a symlink a...2015

💬Community

1
Bugzilla
CVE-2015-1038 p7zip: directory traversal vulnerability2015-01-06
CVE-2015-1038 — Link Following in 7-zip P7zip | cvebase