cbcvebase.
CVE-2015-2304
published 2015-03-15

CVE-2015-2304: Absolute path traversal vulnerability in bsdcpio in libarchive 3.1.2 and earlier allows remote attackers to write to arbitrary files via a full pathname in an…

PriorityP340medium6.4CVSS 2.0
AVNACLAuNCNIPAP
EPSS
4.89%
91.2th percentile
Absolute path traversal vulnerability in bsdcpio in libarchive 3.1.2 and earlier allows remote attackers to write to arbitrary files via a full pathname in an archive.

Affected

12 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debianlibarchive< libarchive 3.1.2-11 (bookworm)libarchive 3.1.2-11 (bookworm)
libarchivelibarchive<= 3.1.2
libarchivelibarchive>= 0 < 3.1.2-113.1.2-11
libarchivelibarchive>= 0 < 3.1.2-113.1.2-11
libarchivelibarchive>= 0 < 3.1.2-113.1.2-11
libarchivelibarchive>= 0 < 3.1.2-113.1.2-11
libarchivelibarchive>= 0 < 3.1.2-7ubuntu2.13.1.2-7ubuntu2.1
opensuseopensuse
opensuseopensuse

CVSS provenance

nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:P
osv6.4MEDIUM
vendor_debian6.4MEDIUM
vendor_redhat6.4MEDIUM
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.