VulnerabilityModified
CVE-2015-0557
Open-source ARJ archiver 3.10.22 does not properly remove leading slashes from paths, which allows remote attackers to conduct absolute path traversal attacks and write to arbitrary files via multiple leading slashes in a path in an ARJ archive.
MEDIUM 5.8EPSS 3.34%
Does this matter?
Lower severity and a low EPSS score (3.34%). Track it; it rarely justifies an emergency change on its own.
Description
Open-source ARJ archiver 3.10.22 does not properly remove leading slashes from paths, which allows remote attackers to conduct absolute path traversal attacks and write to arbitrary files via multiple leading slashes in a path in an ARJ archive.
- CVSS 2.0
- 5.8 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:P
- EPSS
- 3.34% probability · 88th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- arj software/arj archiver · fedoraproject/fedora
- Source
- security@debian.org
References
- http://lists.fedoraproject.org/pipermail/package-announce/2015-April/154518.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-April/154605.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-April/155011.html
- http://www.debian.org/security/2015/dsa-3213
- http://www.mandriva.com/security/advisories?name=MDVSA-2015:201
- http://www.openwall.com/lists/oss-security/2015/01/03/5
- http://www.openwall.com/lists/oss-security/2015/01/05/9
- http://www.securityfocus.com/bid/71895
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=774435Exploit
- https://security.gentoo.org/glsa/201612-15
- http://lists.fedoraproject.org/pipermail/package-announce/2015-April/154518.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-April/154605.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-April/155011.html
- http://www.debian.org/security/2015/dsa-3213
- http://www.mandriva.com/security/advisories?name=MDVSA-2015:201
- http://www.openwall.com/lists/oss-security/2015/01/03/5
- http://www.openwall.com/lists/oss-security/2015/01/05/9
- http://www.securityfocus.com/bid/71895
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=774435Exploit
- https://security.gentoo.org/glsa/201612-15
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.