3.3
CVSSv3

CVE-2015-0858

Published: 06/05/2016 Updated: 09/05/2016
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 3.3 | Impact Score: 1.4 | Exploitability Score: 1.8
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cool Projects TarDiff allows local users to write to arbitrary files via a symlink attack on a pathname in a /tmp/tardiff-$$ temporary directory.

Vulnerable Product Search on Vulmon Subscribe to Product

debian debian linux 8.0

tardiff project tardiff -

Vendor Advisories

Several vulnerabilities were discovered in tardiff, a tarball comparison tool The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2015-0857 Rainer Mueller and Florian Weimer discovered that tardiff is prone to shell command injections via shell meta-characters in filenames in tar files or via shell ...