CVE-2015-0557
Summary
| CVE | CVE-2015-0557 |
|---|---|
| State | PUBLISHED |
| Assigner | debian |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-04-08 18:59:04 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | Open-source ARJ archiver 3.10.22 does not properly remove leading slashes from paths, which allows remote attackers to conduct absolute path traversal attacks and write to arbitrary files via multiple leading slashes in a path in an ARJ archive. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
PartialAV:N/AC:M/Au:N/C:N/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Arj Software | Arj Archiver | All | All | All | All |
| Operating System | Fedoraproject | Fedora | 20 | All | All | All |
| Operating System | Fedoraproject | Fedora | 21 | All | All | All |
| Operating System | Fedoraproject | Fedora | 22 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [SECURITY] Fedora 20 Update: arj-3.10.22-22.fc20 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | |
| Debian -- Security Information -- DSA-3213-1 arj | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| Support / Security / Advisories / / MDVSA-2015:201 | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| #774435 - arj: CVE-2015-0557: directory traversal via //multiple/leading/slash - Debian Bug report logs | af854a3a-2127-422b-91ae-364da2661108 | bugs.debian.org | Exploit |
| ARJ: Multiple vulnerabilities (GLSA 201612-15) — Gentoo security | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | |
| ARJ CVE-2015-0557 Directory Traversal Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| [SECURITY] Fedora 22 Update: arj-3.10.22-22.fc22 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | |
| oss-security - CVE Request: arj: symlink directory traversal and directory traversal via //multiple/leading/slash | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| [SECURITY] Fedora 21 Update: arj-3.10.22-22.fc21 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | |
| oss-security - Re: CVE Request: arj: symlink directory traversal and directory traversal via //multiple/leading/slash | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.