CVE-2015-2304
published 2015-03-15CVE-2015-2304: Absolute path traversal vulnerability in bsdcpio in libarchive 3.1.2 and earlier allows remote attackers to write to arbitrary files via a full pathname in an…
PriorityP340medium6.4CVSS 2.0
AVNACLAuNCNIPAP
EPSS
4.89%
91.2th percentile
Absolute path traversal vulnerability in bsdcpio in libarchive 3.1.2 and earlier allows remote attackers to write to arbitrary files via a full pathname in an archive.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | libarchive | < libarchive 3.1.2-11 (bookworm) | libarchive 3.1.2-11 (bookworm) |
| libarchive | libarchive | <= 3.1.2 | — |
| libarchive | libarchive | >= 0 < 3.1.2-11 | 3.1.2-11 |
| libarchive | libarchive | >= 0 < 3.1.2-11 | 3.1.2-11 |
| libarchive | libarchive | >= 0 < 3.1.2-11 | 3.1.2-11 |
| libarchive | libarchive | >= 0 < 3.1.2-11 | 3.1.2-11 |
| libarchive | libarchive | >= 0 < 3.1.2-7ubuntu2.1 | 3.1.2-7ubuntu2.1 |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
CVSS provenance
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:P
osv6.4MEDIUM
vendor_debian6.4MEDIUM
vendor_redhat6.4MEDIUM
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-fg4c-3cxq-4rf3: Absolute path traversal vulnerability in bsdcpio in libarchive 3
ghsa_unreviewed·2022-05-14
CVE-2015-2304 [MEDIUM] CWE-22 GHSA-fg4c-3cxq-4rf3: Absolute path traversal vulnerability in bsdcpio in libarchive 3
Absolute path traversal vulnerability in bsdcpio in libarchive 3.1.2 and earlier allows remote attackers to write to arbitrary files via a full pathname in an archive.
OSV
libarchive vulnerabilities
osv·2015-03-25·CVSS 5.0
CVE-2015-2304 [MEDIUM] libarchive vulnerabilities
libarchive vulnerabilities
It was discovered that the libarchive bsdcpio utility extracted absolute
paths by default without using the --insecure flag, contrary to
expectations. If a user or automated system were tricked into extracting
cpio archives containing absolute paths, a remote attacker may be able to
write to arbitrary files. (CVE-2015-2304)
Fabian Yamaguchi discovered that libarchive incorrectly handled certain
type conversions. A remote attacker could possibly use this issue to cause
libarchive to crash, resulting in a denial of service. This issue only
affected Ubuntu 12.04 LTS. (CVE-2013-0211)
OSV
CVE-2015-2304: Absolute path traversal vulnerability in bsdcpio in libarchive 3
osv·2015-03-15·CVSS 6.4
CVE-2015-2304 [MEDIUM] CVE-2015-2304: Absolute path traversal vulnerability in bsdcpio in libarchive 3
Absolute path traversal vulnerability in bsdcpio in libarchive 3.1.2 and earlier allows remote attackers to write to arbitrary files via a full pathname in an archive.
BSD
FreeBSD-SA-16:22.libarchive: Directory traversal in cpio(1)
bsd_advisories·2016-05-31·CVSS 6.4
CVE-2015-2304 [MEDIUM] FreeBSD-SA-16:22.libarchive: Directory traversal in cpio(1)
FreeBSD-SA-16:22.libarchive Security Advisory
The FreeBSD Project
Topic: Directory traversal in cpio(1)
Category: contrib
Module: libarchive
Announced: 2016-05-31
Credits: Alexander Cherepanov
Affects: All supported versions of FreeBSD
Corrected: 2016-05-21 09:03:45 UTC (stable/10, 10.3-STABLE)
2016-05-31 16:35:03 UTC (releng/10.3, 10.3-RELEASE-p4)
2016-05-31 16:33:56 UTC (releng/10.2, 10.2-RELEASE-p18)
2016-05-31 16:32:42 UTC (releng/10.1, 10.1-RELEASE-p35)
2016-05-21 09:27:30 UTC (stable/9, 9.3-STABLE)
2016-05-31 16:23:56 UTC (releng/9.3, 9.3-RELEASE-p43)
CVE Name: CVE-2015-2304
For general information regarding FreeBSD Security Advisories,
including descriptions of the fields above, security branches, and the
following sections, please visit .
I. Background
The libarchive(3) librar
Ubuntu
libarchive vulnerabilities
vendor_ubuntu·2015-03-25·CVSS 5.0
CVE-2013-0211 [MEDIUM] libarchive vulnerabilities
Title: libarchive vulnerabilities
Summary: libarchive could be made to crash or overwrite files.
It was discovered that the libarchive bsdcpio utility extracted absolute
paths by default without using the --insecure flag, contrary to
expectations. If a user or automated system were tricked into extracting
cpio archives containing absolute paths, a remote attacker may be able to
write to arbitrary files. (CVE-2015-2304)
Fabian Yamaguchi discovered that libarchive incorrectly handled certain
type conversions. A remote attacker could possibly use this issue to cause
libarchive to crash, resulting in a denial of service. This issue only
affected Ubuntu 12.04 LTS. (CVE-2013-0211)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
libarchive: directory traversal in bsdcpio
vendor_redhat·2015-01-16·CVSS 6.4
CVE-2015-2304 [MEDIUM] CWE-22 libarchive: directory traversal in bsdcpio
libarchive: directory traversal in bsdcpio
Absolute path traversal vulnerability in bsdcpio in libarchive 3.1.2 and earlier allows remote attackers to write to arbitrary files via a full pathname in an archive.
Statement: Red Hat Product Security has rated this issue as having Low security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Package: libarchive (Red Hat Enterprise Linux 6) - Will not fix
Package: libarchive (Red Hat Enterprise Linux 7) - Will not fix
Debian
CVE-2015-2304: libarchive - Absolute path traversal vulnerability in bsdcpio in libarchive 3.1.2 and earlier...
vendor_debian·2015·CVSS 6.4
CVE-2015-2304 [MEDIUM] CVE-2015-2304: libarchive - Absolute path traversal vulnerability in bsdcpio in libarchive 3.1.2 and earlier...
Absolute path traversal vulnerability in bsdcpio in libarchive 3.1.2 and earlier allows remote attackers to write to arbitrary files via a full pathname in an archive.
Scope: local
bookworm: resolved (fixed in 3.1.2-11)
bullseye: resolved (fixed in 3.1.2-11)
forky: resolved (fixed in 3.1.2-11)
sid: resolved (fixed in 3.1.2-11)
trixie: resolved (fixed in 3.1.2-11)
No detection rules found.
No public exploits indexed.
http://advisories.mageia.org/MGASA-2015-0106.htmlhttp://lists.opensuse.org/opensuse-updates/2015-03/msg00065.htmlhttp://www.debian.org/security/2015/dsa-3180http://www.mandriva.com/security/advisories?name=MDVSA-2015:157http://www.openwall.com/lists/oss-security/2015/01/07/5http://www.openwall.com/lists/oss-security/2015/01/16/7http://www.securitytracker.com/id/1035996http://www.ubuntu.com/usn/USN-2549-1https://github.com/libarchive/libarchive/commit/59357157706d47c365b2227739e17daba3607526https://github.com/libarchive/libarchive/pull/110https://groups.google.com/forum/#%21msg/libarchive-discuss/dN9y1VvE1Qk/Z9uerigjQn0Jhttps://security.gentoo.org/glsa/201701-03https://www.freebsd.org/security/advisories/FreeBSD-SA-16:22.libarchive.aschttp://advisories.mageia.org/MGASA-2015-0106.htmlhttp://lists.opensuse.org/opensuse-updates/2015-03/msg00065.htmlhttp://www.debian.org/security/2015/dsa-3180http://www.mandriva.com/security/advisories?name=MDVSA-2015:157http://www.openwall.com/lists/oss-security/2015/01/07/5http://www.openwall.com/lists/oss-security/2015/01/16/7http://www.securitytracker.com/id/1035996http://www.ubuntu.com/usn/USN-2549-1https://github.com/libarchive/libarchive/commit/59357157706d47c365b2227739e17daba3607526https://github.com/libarchive/libarchive/pull/110https://groups.google.com/forum/#%21msg/libarchive-discuss/dN9y1VvE1Qk/Z9uerigjQn0Jhttps://security.gentoo.org/glsa/201701-03https://www.freebsd.org/security/advisories/FreeBSD-SA-16:22.libarchive.asc
2015-03-15
Published