CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
Percentile
73.6%
Stanislav Brabec discovered errors in yamt’s path name
handling that lead to buffer overflows and directory traversal
issues. When processing a file with a maliciously crafted ID3
tag, yamt might overwrite arbitrary files or possibly execute
arbitrary code.
The SuSE package ChangeLog contains:
Several security fixes (#49337):
directory traversal in rename
directory traversal in sort
buffer overflow in sort
buffer overflow in rename