CVE-2015-2304

Published

Severity

CVSS v3:
N/A
CVSS v2:
6.4 MEDIUM

Description

Absolute path traversal vulnerability in bsdcpio in libarchive 3.1.2 and earlier allows remote attackers to write to arbitrary files via a full pathname in an archive.

References

Configurations

CPE23Version StartVersion EndExact Version
cpe:2.3:a:libarchive:libarchive:*:*:*:*:*:x64:*:*n/a3.1.2 (including)*
cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:*n/an/a12.04
cpe:2.3:o:canonical:ubuntu_linux:14.10:*:*:*:*:*:*:*n/an/a14.10
cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*n/an/a14.04
cpe:2.3:o:opensuse:opensuse:13.1:*:*:*:*:*:*:*n/an/a13.1
cpe:2.3:o:opensuse:opensuse:13.2:*:*:*:*:*:*:*n/an/a13.2

External Links