CVE-2015-2060
Last modified
CVE-2015-2060 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. cabextract before 1.6 does not properly check for leading slashes when extracting files, which allows remote attackers to conduct absolute directory traversal attacks via a malformed UTF-8 character that is changed to a UTF-8 encoded slash.. EPSS estimates a 2.31% chance of exploitation in the next 30 days.
Description
cabextract before 1.6 does not properly check for leading slashes when extracting files, which allows remote attackers to conduct absolute directory traversal attacks via a malformed UTF-8 character that is changed to a UTF-8 encoded slash.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cabextract Project | Cabextract | < 1.6 |
References
- http://lists.fedoraproject.org/pipermail/package-announce/2015-March/151145.htmlIssue Tracking, Patch, Third Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2015-March/151147.htmlIssue Tracking, Patch, Third Party Advisory
- http://www.cabextract.org.uk/Vendor Advisory
- http://www.openwall.com/lists/oss-security/2015/02/18/3Exploit, Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2015/02/23/16Mailing List, Mitigation, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2015/02/23/24Mailing List, Mitigation, Third Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2015-March/151145.htmlIssue Tracking, Patch, Third Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2015-March/151147.htmlIssue Tracking, Patch, Third Party Advisory
- http://www.cabextract.org.uk/Vendor Advisory
- http://www.openwall.com/lists/oss-security/2015/02/18/3Exploit, Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2015/02/23/16Mailing List, Mitigation, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2015/02/23/24Mailing List, Mitigation, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2015-2060?
How severe is CVE-2015-2060?
How do I fix CVE-2015-2060?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2015
- CVE-2015-2052Stack-based buffer overflow in the DIR-645 Wired/Wireless Ro…
- CVE-2015-2053The log viewer in McAfee Agent (MA) before 4.8.0 Patch 3 and…
- CVE-2015-2054CRLF injection vulnerability in export.cfg in the web-based …
- CVE-2015-2055Zhone GPON 2520 with firmware R4.0.2.566b allows remote atta…
- CVE-2015-2058c2s/c2s.c in Jabber Open Source Server 2.3.2 and earlier tru…
- CVE-2015-2059The stringprep_utf8_to_ucs4 function in libin before 1.31, a…
- CVE-2015-2061Heap-based buffer overflow in the browser plugin for PTC Cre…
- CVE-2015-2062Multiple SQL injection vulnerabilities in the Huge-IT Slider…7.2
- CVE-2015-2063Integer overflow in unace 1.2b allows remote attackers to ca…
- CVE-2015-2064Multiple cross-site scripting (XSS) vulnerabilities in DLGua…
- CVE-2015-2065SQL injection vulnerability in videogalleryrss.php in the Ap…
- CVE-2015-2066SQL injection vulnerability in DLGuard 4.5 allows remote att…
Are you affected by CVE-2015-2060?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
