Lucene search

K
mageiaGentoo FoundationMGASA-2015-0252
HistoryJul 01, 2015 - 3:40 p.m.

Updated p7zip package fixes security vulnerability

2015-07-0115:40:22
Gentoo Foundation
advisories.mageia.org
16

CVSS2

5.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:P/A:P

EPSS

0.023

Percentile

90.0%

Alexander Cherepanov discovered that p7zip is susceptible to a directory traversal vulnerability. While extracting an archive, it will extract symlinks and then follow them if they are referenced in further entries. This can be exploited by a rogue archive to write files outside the current directory (CVE-2015-1038).

OSVersionArchitecturePackageVersionFilename
Mageia4noarchp7zip< 9.20.1-4.1p7zip-9.20.1-4.1.mga4
Mageia5noarchp7zip< 9.20.1-6.1p7zip-9.20.1-6.1.mga5

CVSS2

5.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:P/A:P

EPSS

0.023

Percentile

90.0%