5.8
CVSSv2

CVE-2015-0557

Published: 08/04/2015 Updated: 01/07/2017
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
VMScore: 516
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:P

Vulnerability Summary

Open-source ARJ archiver 3.10.22 does not properly remove leading slashes from paths, which allows remote malicious users to conduct absolute path traversal attacks and write to arbitrary files via multiple leading slashes in a path in an ARJ archive.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

arj software arj archiver

fedoraproject fedora 22

fedoraproject fedora 21

fedoraproject fedora 20

Vendor Advisories

Multiple vulnerabilities have been discovered in arj, an open source version of the arj archiver The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2015-0556 Jakub Wilk discovered that arj follows symlinks created during unpacking of an arj archive A remote attacker could use this flaw to perform ...
Debian Bug report logs - #774434 arj: CVE-2015-0556: symlink directory traversal Package: arj; Maintainer for arj is Guillem Jover <guillem@debianorg>; Source for arj is src:arj (PTS, buildd, popcon) Reported by: Jakub Wilk <jwilk@debianorg> Date: Fri, 2 Jan 2015 17:57:02 UTC Severity: normal Tags: security Foun ...
Debian Bug report logs - #774015 arj: CVE-2015-2782: free(): invalid pointer Package: arj; Maintainer for arj is Guillem Jover <guillem@debianorg>; Source for arj is src:arj (PTS, buildd, popcon) Reported by: Jakub Wilk <jwilk@debianorg> Date: Sat, 27 Dec 2014 11:57:01 UTC Severity: important Tags: security Found ...
Debian Bug report logs - #774435 arj: CVE-2015-0557: directory traversal via //multiple/leading/slash Package: arj; Maintainer for arj is Guillem Jover <guillem@debianorg>; Source for arj is src:arj (PTS, buildd, popcon) Reported by: Jakub Wilk <jwilk@debianorg> Date: Fri, 2 Jan 2015 17:57:07 UTC Severity: normal ...