VulnerabilityModified
CVE-2015-2060
cabextract before 1.6 does not properly check for leading slashes when extracting files, which allows remote attackers to conduct absolute directory traversal attacks via a malformed UTF-8 character that is changed to a UTF-8 encoded slash.
MEDIUM 5.3EPSS 2.31%
Does this matter?
Lower severity and a low EPSS score (2.31%). Track it; it rarely justifies an emergency change on its own.
Description
cabextract before 1.6 does not properly check for leading slashes when extracting files, which allows remote attackers to conduct absolute directory traversal attacks via a malformed UTF-8 character that is changed to a UTF-8 encoded slash.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- EPSS
- 2.31% probability · 82th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- cabextract project/cabextract
- Source
- cve@mitre.org
References
- http://lists.fedoraproject.org/pipermail/package-announce/2015-March/151145.htmlIssue Tracking, Patch, Third Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2015-March/151147.htmlIssue Tracking, Patch, Third Party Advisory
- http://www.cabextract.org.uk/Vendor Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2015:064Broken Link
- http://www.openwall.com/lists/oss-security/2015/02/18/3Exploit, Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2015/02/23/16Mailing List, Mitigation, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2015/02/23/24Mailing List, Mitigation, Third Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2015-March/151145.htmlIssue Tracking, Patch, Third Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2015-March/151147.htmlIssue Tracking, Patch, Third Party Advisory
- http://www.cabextract.org.uk/Vendor Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2015:064Broken Link
- http://www.openwall.com/lists/oss-security/2015/02/18/3Exploit, Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2015/02/23/16Mailing List, Mitigation, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2015/02/23/24Mailing List, Mitigation, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.