CVE-2015-2304Path Traversal in Libarchive

CWE-22Path Traversal9 documents8 sources
Severity
6.4MEDIUMNVD
OSV5.0
EPSS
3.5%
top 12.35%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 15
Latest updateMay 14

Description

Absolute path traversal vulnerability in bsdcpio in libarchive 3.1.2 and earlier allows remote attackers to write to arbitrary files via a full pathname in an archive.

CVSS vector

AV:N/AC:L/C:N/I:P/A:PExploitability: 10.0 | Impact: 4.9

Affected Packages5 packages

debiandebian/libarchive< libarchive 3.1.2-11 (bookworm)
Debianlibarchive/libarchive< 3.1.2-11+3
Ubuntulibarchive/libarchive< 3.1.2-7ubuntu2.1
NVDopensuse/opensuse13.1, 13.2+1

Also affects: Ubuntu Linux 12.04, 14.04, 14.10

🔴Vulnerability Details

3
GHSA
GHSA-fg4c-3cxq-4rf3: Absolute path traversal vulnerability in bsdcpio in libarchive 32022-05-14
OSV
libarchive vulnerabilities2015-03-25
OSV
CVE-2015-2304: Absolute path traversal vulnerability in bsdcpio in libarchive 32015-03-15

📋Vendor Advisories

4
BSD
FreeBSD-SA-16:22.libarchive: Directory traversal in cpio(1)2016-05-31
Ubuntu
libarchive vulnerabilities2015-03-25
Red Hat
libarchive: directory traversal in bsdcpio2015-01-16
Debian
CVE-2015-2304: libarchive - Absolute path traversal vulnerability in bsdcpio in libarchive 3.1.2 and earlier...2015

💬Community

1
Bugzilla
CVE-2015-2304 libarchive: directory traversal in bsdcpio2015-02-13