CVE-2022-4515
Summary
| CVE | CVE-2022-4515 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-12-20 19:15:00 UTC |
| Updated | 2023-01-03 17:22:00 UTC |
| Description | A flaw was found in Exuberant Ctags in the way it handles the "-o" option. This option specifies the tag filename. A crafted tag filename specified in the command line or in the configuration file results in arbitrary command execution because the externalSortTags() in sort.c calls the system(3) function in an unsafe way. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] [DLA 3254-1] exuberant-ctags security update |
MLIST |
lists.debian.org |
|
| Exuberant Ctags / Code /
[r816]
/tags/ctags-5.8/sort.c |
MISC |
sourceforge.net |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 160658 Oracle Enterprise Linux Security Update for ctags (ELSA-2023-2863)
- 181492 Debian Security Update for exuberant-ctags (DLA 3254-1)
- 182070 Debian Security Update for exuberant-ctags (CVE-2022-4515)
- 199127 Ubuntu Security Notification for exuberant-ctags Vulnerability (USN-5820-1)
- 241511 Red Hat Update for ctags (RHSA-2023:2863)
- 356735 Amazon Linux Security Advisory for ctags : ALAS2-2023-2343
- 378643 Alibaba Cloud Linux Security Update for ctags (ALINUX3-SA-2023:0069)
- 753609 SUSE Enterprise Linux Security Update for ctags (SUSE-SU-2023:0225-1)
- 753612 SUSE Enterprise Linux Security Update for ctags (SUSE-SU-2023:0224-1)
- 904762 Common Base Linux Mariner (CBL-Mariner) Security Update for ctags (12085)
- 904763 Common Base Linux Mariner (CBL-Mariner) Security Update for ctags (12083)
- 906394 Common Base Linux Mariner (CBL-Mariner) Security Update for ctags (12083-2)
- 941100 AlmaLinux Security Update for ctags (ALSA-2023:2863)