SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2015-0557

Open-source ARJ archiver 3.10.22 does not properly remove leading slashes from paths, which allows remote attackers to conduct absolute path traversal attacks and write to arbitrary files via multiple leading slashes in a path in an ARJ archive.

MEDIUM 5.8EPSS 3.34%

Does this matter?

Lower severity and a low EPSS score (3.34%). Track it; it rarely justifies an emergency change on its own.

Description

Open-source ARJ archiver 3.10.22 does not properly remove leading slashes from paths, which allows remote attackers to conduct absolute path traversal attacks and write to arbitrary files via multiple leading slashes in a path in an ARJ archive.

CVSS 2.0
5.8 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:P
EPSS
3.34% probability · 88th percentile
CISA KEV
Not listed
Weakness
CWE-22
Affected
arj software/arj archiver · fedoraproject/fedora
Source
security@debian.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.