CVE-2015-2060Path Traversal in Project Cabextract

CWE-22Path Traversal6 documents6 sources
Severity
5.3MEDIUMNVD
EPSS
8.7%
top 7.48%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 29
Latest updateMay 24

Description

cabextract before 1.6 does not properly check for leading slashes when extracting files, which allows remote attackers to conduct absolute directory traversal attacks via a malformed UTF-8 character that is changed to a UTF-8 encoded slash.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages2 packages

Patches

🔴Vulnerability Details

3
GHSA
GHSA-frjv-h9wg-233r: cabextract before 12022-05-24
CVEList
CVE-2015-2060: cabextract before 12019-11-29
OSV
CVE-2015-2060: cabextract before 12019-11-29

📋Vendor Advisories

1
Debian
CVE-2015-2060: cabextract - cabextract before 1.6 does not properly check for leading slashes when extractin...2015

💬Community

1
Bugzilla
CVE-2015-2060 cabextract: directory traversal with UTF-8 symbols in filenames2015-02-18
CVE-2015-2060 — Path Traversal in Project Cabextract | cvebase