CVE-2015-0557
Last modified
CVE-2015-0557 is a vulnerability of currently unknown severity. Open-source ARJ archiver 3.10.22 does not properly remove leading slashes from paths, which allows remote attackers to conduct absolute path traversal attacks and write to arbitrary files via multiple leading slashes in a path in an ARJ archive.. EPSS estimates a 3.37% chance of exploitation in the next 30 days.
Description
Open-source ARJ archiver 3.10.22 does not properly remove leading slashes from paths, which allows remote attackers to conduct absolute path traversal attacks and write to arbitrary files via multiple leading slashes in a path in an ARJ archive.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Arj Software | Arj Archiver | <= 3.10.22 |
| Fedoraproject | Fedora | 20 |
| Fedoraproject | Fedora | 21 |
| Fedoraproject | Fedora | 22 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2015-0557?
How severe is CVE-2015-0557?
How do I fix CVE-2015-0557?
Are you affected by CVE-2015-0557?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
