CVE-2015-2304 — Path Traversal in Libarchive
Severity
6.4MEDIUMNVD
OSV5.0
EPSS
3.5%
top 12.35%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 15
Latest updateMay 14
Description
Absolute path traversal vulnerability in bsdcpio in libarchive 3.1.2 and earlier allows remote attackers to write to arbitrary files via a full pathname in an archive.
CVSS vector
AV:N/AC:L/C:N/I:P/A:PExploitability: 10.0 | Impact: 4.9
Affected Packages5 packages
Also affects: Ubuntu Linux 12.04, 14.04, 14.10
🔴Vulnerability Details
3📋Vendor Advisories
4Debian▶
CVE-2015-2304: libarchive - Absolute path traversal vulnerability in bsdcpio in libarchive 3.1.2 and earlier...↗2015