CVE-2022-4515
published 2022-12-20CVE-2022-4515: A flaw was found in Exuberant Ctags in the way it handles the "-o" option. This option specifies the tag filename. A crafted tag filename specified in the…
PriorityP339high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.58%
44.3th percentile
A flaw was found in Exuberant Ctags in the way it handles the "-o" option. This option specifies the tag filename. A crafted tag filename specified in the command line or in the configuration file results in arbitrary command execution because the externalSortTags() in sort.c calls the system(3) function in an unsafe way.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | exuberant-ctags | < exuberant-ctags 1:5.9~svn20110310-18 (bookworm) | exuberant-ctags 1:5.9~svn20110310-18 (bookworm) |
| debian | universal-ctags | < exuberant-ctags 1:5.9~svn20110310-18 (bookworm) | exuberant-ctags 1:5.9~svn20110310-18 (bookworm) |
| msrc | azl3_ctags_6.1.0-1_on_azure_linux_3.0 | — | — |
| msrc | azure_linux_3.0_arm | — | — |
| msrc | azure_linux_3.0_x64 | — | — |
| msrc | cbl2_ctags_5.9.20220619.0-7_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| msrc | cm1_ctags_5.8-6_on_cbl_mariner_1.0 | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qr9x-29jh-mg6x: A flaw was found in Exuberant Ctags in the way it handles the "-o" option
ghsa_unreviewed·2022-12-20
CVE-2022-4515 [CRITICAL] CWE-78 GHSA-qr9x-29jh-mg6x: A flaw was found in Exuberant Ctags in the way it handles the "-o" option
A flaw was found in Exuberant Ctags in the way it handles the "-o" option. This option specifies the tag filename. A crafted tag filename specified in the command line or in the configuration file results in arbitrary command execution because the externalSortTags() in sort.c calls the system(3) function in an unsafe way.
OSV
CVE-2022-4515: A flaw was found in Exuberant Ctags in the way it handles the "-o" option
osv·2022-12-20·CVSS 7.8
CVE-2022-4515 [HIGH] CVE-2022-4515: A flaw was found in Exuberant Ctags in the way it handles the "-o" option
A flaw was found in Exuberant Ctags in the way it handles the "-o" option. This option specifies the tag filename. A crafted tag filename specified in the command line or in the configuration file results in arbitrary command execution because the externalSortTags() in sort.c calls the system(3) function in an unsafe way.
Ubuntu
exuberant-ctags vulnerability
vendor_ubuntu·2023-01-24
CVE-2022-4515 exuberant-ctags vulnerability
Title: exuberant-ctags vulnerability
Summary: Exuberant ctags could be make to perform arbitary command execution if run
with maliciously crafted user input
Lorenz Hipp discovered a flaw in exuberant-ctags handling of the tag
filename command-line argument. A crafted tag filename specified
in the command line or in the configuration file could result in
arbitrary command execution.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
ctags: arbitrary command execution via a tag file with a crafted filename
vendor_redhat·2022-12-19·CVSS 7.8
CVE-2022-4515 [HIGH] CWE-78 ctags: arbitrary command execution via a tag file with a crafted filename
ctags: arbitrary command execution via a tag file with a crafted filename
A flaw was found in Exuberant Ctags in the way it handles the "-o" option. This option specifies the tag filename. A crafted tag filename specified in the command line or in the configuration file results in arbitrary command execution because the externalSortTags() in sort.c calls the system(3) function in an unsafe way.
A flaw was found in Exuberant Ctags in the way it handles the "-o" option. This option specifies the tag filename. A crafted tag filename specified in the command line or in the configuration file results in arbitrary command execution because the externalSortTags() in sort.c calls the system(3) function in an unsafe way.
Statement: Exuberant Ctags is not shipped in Red Hat Enterprise Linux 9, th
Microsoft
A flaw was found in Exuberant Ctags in the way it handles the "-o" option. This option specifies the tag filename. A crafted tag filename specified in the command line or in the configuration file res
vendor_msrc·2022-12-13·CVSS 7.8
CVE-2022-4515 [HIGH] CWE-78 A flaw was found in Exuberant Ctags in the way it handles the "-o" option. This option specifies the tag filename. A crafted tag filename specified in the command line or in the configuration file res
A flaw was found in Exuberant Ctags in the way it handles the "-o" option. This option specifies the tag filename. A crafted tag filename specified in the command line or in the configuration file results in arbitrary command execution because the externalSortTags() in sort.c calls the system(3) function in an unsafe way.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX i
Debian
CVE-2022-4515: exuberant-ctags - A flaw was found in Exuberant Ctags in the way it handles the "-o" option. This ...
vendor_debian·2022·CVSS 7.8
CVE-2022-4515 [HIGH] CVE-2022-4515: exuberant-ctags - A flaw was found in Exuberant Ctags in the way it handles the "-o" option. This ...
A flaw was found in Exuberant Ctags in the way it handles the "-o" option. This option specifies the tag filename. A crafted tag filename specified in the command line or in the configuration file results in arbitrary command execution because the externalSortTags() in sort.c calls the system(3) function in an unsafe way.
Scope: local
bookworm: resolved (fixed in 1:5.9~svn20110310-18)
bullseye: resolved (fixed in 1:5.9~svn20110310-14+deb11u1)
forky: resolved (fixed in 1:5.9~svn20110310-18)
sid: resolved (fixed in 1:5.9~svn20110310-18)
trixie: resolved (fixed in 1:5.9~svn20110310-18)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-12-20
Published