CVE-2015-2060
published 2019-11-29CVE-2015-2060: cabextract before 1.6 does not properly check for leading slashes when extracting files, which allows remote attackers to conduct absolute directory traversal…
PriorityP431medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
EPSS
2.31%
81.4th percentile
cabextract before 1.6 does not properly check for leading slashes when extracting files, which allows remote attackers to conduct absolute directory traversal attacks via a malformed UTF-8 character that is changed to a UTF-8 encoded slash.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cabextract_project | cabextract | < 1.6 | 1.6 |
| cabextract_project | cabextract | >= 0 < 1.6-1 | 1.6-1 |
| cabextract_project | cabextract | >= 0 < 1.6-1 | 1.6-1 |
| cabextract_project | cabextract | >= 0 < 1.6-1 | 1.6-1 |
| cabextract_project | cabextract | >= 0 < 1.6-1 | 1.6-1 |
| debian | cabextract | < cabextract 1.6-1 (bookworm) | cabextract 1.6-1 (bookworm) |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv5.3MEDIUM
vendor_debian5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2015-2060: cabextract - cabextract before 1.6 does not properly check for leading slashes when extractin...
vendor_debian·2015·CVSS 5.3
CVE-2015-2060 [MEDIUM] CVE-2015-2060: cabextract - cabextract before 1.6 does not properly check for leading slashes when extractin...
cabextract before 1.6 does not properly check for leading slashes when extracting files, which allows remote attackers to conduct absolute directory traversal attacks via a malformed UTF-8 character that is changed to a UTF-8 encoded slash.
Scope: local
bookworm: resolved (fixed in 1.6-1)
bullseye: resolved (fixed in 1.6-1)
forky: resolved (fixed in 1.6-1)
sid: resolved (fixed in 1.6-1)
trixie: resolved (fixed in 1.6-1)
GHSA
GHSA-frjv-h9wg-233r: cabextract before 1
ghsa_unreviewed·2022-05-24
CVE-2015-2060 [MEDIUM] GHSA-frjv-h9wg-233r: cabextract before 1
cabextract before 1.6 does not properly check for leading slashes when extracting files, which allows remote attackers to conduct absolute directory traversal attacks via a malformed UTF-8 character that is changed to a UTF-8 encoded slash.
OSV
CVE-2015-2060: cabextract before 1
osv·2019-11-29·CVSS 5.3
CVE-2015-2060 [MEDIUM] CVE-2015-2060: cabextract before 1
cabextract before 1.6 does not properly check for leading slashes when extracting files, which allows remote attackers to conduct absolute directory traversal attacks via a malformed UTF-8 character that is changed to a UTF-8 encoded slash.
No detection rules found.
No public exploits indexed.
http://lists.fedoraproject.org/pipermail/package-announce/2015-March/151145.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-March/151147.htmlhttp://www.cabextract.org.uk/http://www.mandriva.com/security/advisories?name=MDVSA-2015:064http://www.openwall.com/lists/oss-security/2015/02/18/3http://www.openwall.com/lists/oss-security/2015/02/23/16http://www.openwall.com/lists/oss-security/2015/02/23/24http://lists.fedoraproject.org/pipermail/package-announce/2015-March/151145.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-March/151147.htmlhttp://www.cabextract.org.uk/http://www.mandriva.com/security/advisories?name=MDVSA-2015:064http://www.openwall.com/lists/oss-security/2015/02/18/3http://www.openwall.com/lists/oss-security/2015/02/23/16http://www.openwall.com/lists/oss-security/2015/02/23/24
2019-11-29
Published