Lucene search

K
nvd[email protected]NVD:CVE-2015-1038
HistoryJan 21, 2015 - 6:59 p.m.

CVE-2015-1038

2015-01-2118:59:51
CWE-59
web.nvd.nist.gov
8

CVSS2

5.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:P/A:P

AI Score

6.4

Confidence

Low

EPSS

0.023

Percentile

90.0%

p7zip 9.20.1 allows remote attackers to write to arbitrary files via a symlink attack in an archive.

Affected configurations

Nvd
Node
fedoraprojectfedoraMatch22
OR
fedoraprojectfedoraMatch23
Node
oraclesolarisMatch10.0
OR
oraclesolarisMatch11.2
Node
7-zipp7zipMatch9.20.1
VendorProductVersionCPE
fedoraprojectfedora22cpe:2.3:o:fedoraproject:fedora:22:*:*:*:*:*:*:*
fedoraprojectfedora23cpe:2.3:o:fedoraproject:fedora:23:*:*:*:*:*:*:*
oraclesolaris10.0cpe:2.3:o:oracle:solaris:10.0:*:*:*:*:*:*:*
oraclesolaris11.2cpe:2.3:o:oracle:solaris:11.2:*:*:*:*:*:*:*
7-zipp7zip9.20.1cpe:2.3:a:7-zip:p7zip:9.20.1:*:*:*:*:*:*:*

CVSS2

5.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:P/A:P

AI Score

6.4

Confidence

Low

EPSS

0.023

Percentile

90.0%