Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2015-0557
Description:Open-source ARJ archiver 3.10.22 does not properly remove leading slashes from paths, which allows remote attackers to conduct absolute path traversal attacks and write to arbitrary files via multiple leading slashes in a path in an ARJ archive.
Test IDs: 1.3.6.1.4.1.25623.1.0.703213   1.3.6.1.4.1.25623.1.1.1.2.2015.188  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2015-0557
BugTraq ID: 71895
http://www.securityfocus.com/bid/71895
Debian Security Information: DSA-3213 (Google Search)
http://www.debian.org/security/2015/dsa-3213
http://lists.fedoraproject.org/pipermail/package-announce/2015-April/155011.html
http://lists.fedoraproject.org/pipermail/package-announce/2015-April/154605.html
http://lists.fedoraproject.org/pipermail/package-announce/2015-April/154518.html
https://security.gentoo.org/glsa/201612-15
http://www.mandriva.com/security/advisories?name=MDVSA-2015:201
http://www.openwall.com/lists/oss-security/2015/01/03/5
http://www.openwall.com/lists/oss-security/2015/01/05/9




© 1998-2025 E-Soft Inc. All rights reserved.