Open-source ARJ archiver 3.10.22 does not properly remove leading slashes...
Vulnerability Description
Open-source ARJ archiver 3.10.22 does not properly remove leading slashes from paths, which allows remote attackers to conduct absolute path traversal attacks and write to arbitrary files via multiple leading slashes in a path in an ARJ archive.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2015-0557
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.mandriva.com/security/advisories?name=MDVSA-2015:201
- http://lists.fedoraproject.org/pipermail/package-announce/2015-April/154605.html
- http://www.openwall.com/lists/oss-security/2015/01/05/9
- https://security.gentoo.org/glsa/201612-15
- http://www.openwall.com/lists/oss-security/2015/01/03/5
- http://lists.fedoraproject.org/pipermail/package-announce/2015-April/155011.html
- http://www.debian.org/security/2015/dsa-3213
- http://lists.fedoraproject.org/pipermail/package-announce/2015-April/154518.html
- http://www.securityfocus.com/bid/71895
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=774435
Affected Vendor
arj software
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.