5.8
CVSSv2

CVE-2015-1038

Published: 21/01/2015 Updated: 08/09/2017
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
VMScore: 516
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:P

Vulnerability Summary

p7zip 9.20.1 allows remote malicious users to write to arbitrary files via a symlink attack in an archive.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

fedoraproject fedora 22

fedoraproject fedora 23

oracle solaris 10.0

oracle solaris 11.2

7-zip p7zip 9.20.1

Vendor Advisories

Debian Bug report logs - #774660 p7zip: CVE-2015-1038: Directory traversal through symlinks Package: p7zip-full; Maintainer for p7zip-full is Robert Luberda <robert@debianorg>; Source for p7zip-full is src:p7zip (PTS, buildd, popcon) Reported by: Alexander Cherepanov <cherepan@mccmeru> Date: Mon, 5 Jan 2015 20:33: ...