Description
Directory traversal vulnerability in the gcab_folder_extract function in libgcab/gcab-folder.c in gcab 0.4 allows remote attackers to write to arbitrary files via crafted path in a CAB file, as demonstrated by "\tmp\moo."
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2015-0565 | Directory traversal vulnerability in the gcab_folder_extract function in libgcab/gcab-folder.c in gcab 0.4 allows remote attackers to write to arbitrary files via crafted path in a CAB file, as demonstrated by "\tmp\moo." |
References
History
No history.
Status: PUBLISHED
Assigner: debian
Published:
Updated: 2024-08-06T04:10:11.076Z
Reserved: 2015-01-05T00:00:00.000Z
Link: CVE-2015-0552
No data.
Status : Modified
Published: 2015-01-15T15:59:26.623
Modified: 2026-05-06T22:30:45.220
Link: CVE-2015-0552
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD