Lucene search

K
cve[email protected]CVE-2015-2304
HistoryMar 15, 2015 - 7:59 p.m.

CVE-2015-2304

2015-03-1519:59:00
CWE-22
web.nvd.nist.gov
46
cve-2015-2304
nvd
vulnerability
libarchive
remote attackers
path traversal
arbitrary files

6.4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:P/A:P

7.4 High

AI Score

Confidence

High

0.011 Low

EPSS

Percentile

84.9%

Absolute path traversal vulnerability in bsdcpio in libarchive 3.1.2 and earlier allows remote attackers to write to arbitrary files via a full pathname in an archive.

Affected configurations

NVD
Node
libarchivelibarchiveRange3.1.2x64
Node
canonicalubuntu_linuxMatch12.04lts
OR
canonicalubuntu_linuxMatch14.04lts
OR
canonicalubuntu_linuxMatch14.10
OR
opensuseopensuseMatch13.1
OR
opensuseopensuseMatch13.2
CPENameOperatorVersion
libarchive:libarchivelibarchivele3.1.2

6.4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:P/A:P

7.4 High

AI Score

Confidence

High

0.011 Low

EPSS

Percentile

84.9%