8.8
CVSSv3

CVE-2016-1244

Published: 03/10/2016 Updated: 15/03/2024
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

The extractTree function in unADF allows remote malicious users to execute arbitrary code via shell metacharacters in a directory name in an adf file.

Vulnerable Product Search on Vulmon Subscribe to Product

unadf project unadf 1.0

debian debian linux 8.0

debian debian linux 7.0

Vendor Advisories

Debian Bug report logs - #838248 unadf: CVE-2016-1243 and CVE-2016-1244 Package: src:unadf; Maintainer for src:unadf is Debian QA Group <packages@qadebianorg>; Reported by: Luciano Bello <luciano@debianorg> Date: Mon, 19 Sep 2016 02:45:02 UTC Severity: grave Tags: patch, security, upstream Found in version unadf/ ...
Tuomas Räsänen discovered two vulnerabilities in unADF, a tool to extract files from an Amiga Disk File dump (adf): CVE-2016-1243 A stack buffer overflow in the function extractTree() might allow an attacker, with control on the content of a ADF file, to execute arbitrary code with the privileges of the program execution CVE-2016-1 ...

Github Repositories

A free, portable and open implementation of the Amiga filesystem

ADFlib (Amiga Disk File library) Introduction The ADFlib is a free, portable and open implementation of the Amiga filesystem The initial release was in 1999 It supports: floppy and hard disk images ("dumps") mount, unmount, create a device image (an adf file) or a volume (a partition inside a device) create, open, close, delete, rename/move a file or a directory fi