Búsqueda de    
Vulnerabilidad   
    Buscar 219043 Descripciones CVE y
99761 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.703289
Categoría:Debian Local Security Checks
Título:Debian Security Advisory DSA 3289-1 (p7zip - security update)
Resumen:Alexander Cherepanov discovered that;p7zip is susceptible to a directory traversal vulnerability. While extracting an;archive, it will extract symlinks and then follow them if they are referenced in;further entries. This can be exploited by a rogue archive to write;files outside the current directory.
Descripción:Summary:
Alexander Cherepanov discovered that
p7zip is susceptible to a directory traversal vulnerability. While extracting an
archive, it will extract symlinks and then follow them if they are referenced in
further entries. This can be exploited by a rogue archive to write
files outside the current directory.

Affected Software/OS:
p7zip on Debian Linux

Solution:
For the oldstable distribution (wheezy),
this problem has been fixed in version 9.20.1~
dfsg.1-4+deb7u1.

For the stable distribution (jessie), this problem has been fixed in
version 9.20.1~
dfsg.1-4.1+deb8u1.

For the unstable distribution (sid), this problem has been fixed in
version 9.20.1~
dfsg.1-4.2.

We recommend that you upgrade your p7zip packages.

CVSS Score:
5.8

CVSS Vector:
AV:N/AC:M/Au:N/C:N/I:P/A:P

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2015-1038
BugTraq ID: 71890
http://www.securityfocus.com/bid/71890
Debian Security Information: DSA-3289 (Google Search)
http://www.debian.org/security/2015/dsa-3289
http://lists.fedoraproject.org/pipermail/package-announce/2015-December/174245.html
http://lists.fedoraproject.org/pipermail/package-announce/2015-December/173245.html
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=774660
https://bugzilla.redhat.com/show_bug.cgi?id=1179505
http://www.openwall.com/lists/oss-security/2015/01/11/2
SuSE Security Announcement: openSUSE-SU-2015:1162 (Google Search)
http://lists.opensuse.org/opensuse-updates/2015-07/msg00000.html
XForce ISS Database: p7zip-cve20151038-symlink(99970)
https://exchange.xforce.ibmcloud.com/vulnerabilities/99970
CopyrightCopyright (c) 2015 Greenbone Networks GmbH http://greenbone.net

Esta es sólo una de 99761 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2024 E-Soft Inc. Todos los derechos reservados.