6.4
CVSSv2

CVE-2015-0552

Published: 15/01/2015 Updated: 30/10/2018
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
VMScore: 570
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:P

Vulnerability Summary

Directory traversal vulnerability in the gcab_folder_extract function in libgcab/gcab-folder.c in gcab 0.4 allows remote malicious users to write to arbitrary files via crafted path in a CAB file, as demonstrated by "\tmp\moo."

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

gnome gcab 0.4

opensuse opensuse 13.1

opensuse opensuse 13.2

Vendor Advisories

Debian Bug report logs - #774580 gcab: CVE-2015-0552: directory traversal Package: gcab; Maintainer for gcab is Stephen Kitt <skitt@debianorg>; Source for gcab is src:gcab (PTS, buildd, popcon) Reported by: Jakub Wilk <jwilk@debianorg> Date: Sun, 4 Jan 2015 17:15:02 UTC Severity: normal Tags: security Found in v ...