Vulnerability CVE-2015-0556: Information

Description

Open-source ARJ archiver 3.10.22 allows remote attackers to conduct directory traversal attacks via a symlink attack in an ARJ archive.

Severity: MEDIUM (5.8)

Published: April 8, 2015
Modified: July 1, 2017
Error type identifier: CWE-59

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
arjsisyphus3.10.22-alt83.10.22-alt9ALT-PU-2022-2889-1308725Fixed
arjsisyphus_e2k3.10.22-alt83.10.22-alt9ALT-PU-2022-6685-1-Fixed
arjsisyphus_mipsel3.10.22-alt83.10.22-alt9ALT-PU-2022-6732-1-Fixed
arjsisyphus_riscv643.10.22-alt83.10.22-alt9ALT-PU-2022-6736-1-Fixed
arjp103.10.22-alt93.10.22-alt9ALT-PU-2022-2941-1308983Fixed
arjp10_e2k3.10.22-alt93.10.22-alt9ALT-PU-2022-6796-1-Fixed
arjc10f13.10.22-alt93.10.22-alt9ALT-PU-2022-2941-1308983Fixed
arjc9f23.10.22-alt93.10.22-alt9ALT-PU-2022-3067-1309706Fixed

References to Advisories, Solutions, and Tools

    1. Configuration 1

      cpe:2.3:a:arj_software:arj_archiver:*:*:*:*:*:*:*:*
      End including
      3.10.22

      Configuration 2

      cpe:2.3:o:fedoraproject:fedora:22:*:*:*:*:*:*:*

      cpe:2.3:o:fedoraproject:fedora:20:*:*:*:*:*:*:*

      cpe:2.3:o:fedoraproject:fedora:21:*:*:*:*:*:*:*