Debian Tardiff vulnerabilities
2 known vulnerabilities affecting debian/tardiff.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1LOW1
Vulnerabilities
Page 1 of 1
CVE-2015-0857P3CRITICALCVSS 9.8fixed in tardiff 0.1-5 (bookworm)2015
CVE-2015-0857 [CRITICAL] CVE-2015-0857: tardiff - Cool Projects TarDiff allows remote attackers to execute arbitrary commands via ...
Cool Projects TarDiff allows remote attackers to execute arbitrary commands via shell metacharacters in the name of a (1) tar file or (2) file within a tar file.
Scope: local
bookworm: resolved (fixed in 0.1-5)
bullseye: resolved (fixed in 0.1-5)
forky: resolved (fixed in 0.1-5)
sid: resolved (fixed in 0.1-5)
trixie: resolved (fixed in 0.1-5)
debian
CVE-2015-0858P4LOWCVSS 3.3fixed in tardiff 0.1-3 (bookworm)2015
CVE-2015-0858 [LOW] CVE-2015-0858: tardiff - Cool Projects TarDiff allows local users to write to arbitrary files via a symli...
Cool Projects TarDiff allows local users to write to arbitrary files via a symlink attack on a pathname in a /tmp/tardiff-$$ temporary directory.
Scope: local
bookworm: resolved (fixed in 0.1-3)
bullseye: resolved (fixed in 0.1-3)
forky: resolved (fixed in 0.1-3)
sid: resolved (fixed in 0.1-3)
trixie: resolved (fixed in 0.1-3)
debian