CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:N/AC:M/Au:N/C:N/I:P/A:P
AI Score
Confidence
Low
EPSS
Percentile
90.0%
p7zip 9.20.1 allows remote attackers to write to arbitrary files via a symlink attack in an archive.
Vendor | Product | Version | CPE |
---|---|---|---|
fedoraproject | fedora | 22 | cpe:2.3:o:fedoraproject:fedora:22:*:*:*:*:*:*:* |
fedoraproject | fedora | 23 | cpe:2.3:o:fedoraproject:fedora:23:*:*:*:*:*:*:* |
oracle | solaris | 10.0 | cpe:2.3:o:oracle:solaris:10.0:*:*:*:*:*:*:* |
oracle | solaris | 11.2 | cpe:2.3:o:oracle:solaris:11.2:*:*:*:*:*:*:* |
7-zip | p7zip | 9.20.1 | cpe:2.3:a:7-zip:p7zip:9.20.1:*:*:*:*:*:*:* |
lists.fedoraproject.org/pipermail/package-announce/2015-December/173245.html
lists.fedoraproject.org/pipermail/package-announce/2015-December/174245.html
lists.opensuse.org/opensuse-updates/2015-07/msg00000.html
www.debian.org/security/2015/dsa-3289
www.openwall.com/lists/oss-security/2015/01/11/2
www.oracle.com/technetwork/topics/security/bulletinjul2015-2511963.html
www.securityfocus.com/bid/71890
bugs.debian.org/cgi-bin/bugreport.cgi?bug=774660
bugzilla.redhat.com/show_bug.cgi?id=1179505
exchange.xforce.ibmcloud.com/vulnerabilities/99970