CVE-2020-29050
Summary
| CVE | CVE-2020-29050 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-01-10 14:10:00 UTC |
| Updated | 2022-04-01 15:19:00 UTC |
| Description | SphinxSearch in Sphinx Technologies Sphinx through 3.1.1 allows directory traversal (in conjunction with CVE-2019-14511) because the mysql client can be used for CALL SNIPPETS and load_file operations on a full pathname (e.g., a file in the /etc directory). NOTE: this is unrelated to CMUSphinx. |
NVD Known Affected Configurations (CPE 2.3)
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 178987 Debian Security Update for sphinxsearch (DSA 5036-1)
- 179007 Debian Security Update for sphinxsearch (DLA 2882-1)
- 751738 OpenSUSE Security Update for sphinx (openSUSE-SU-2022:0046-1)
- 751770 OpenSUSE Security Update for sphinx (openSUSE-SU-2022:0054-1)