elfutils '/libelf/elf_begin.c' Directory Traversal Vulnerability
BID:71804
Info
elfutils '/libelf/elf_begin.c' Directory Traversal Vulnerability
| Bugtraq ID: | 71804 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-9447 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 29 2014 12:00AM |
| Updated: | May 07 2015 05:22PM |
| Credit: | Alexander Cherepanov |
| Vulnerable: |
Ubuntu Ubuntu Linux 12.04 LTS i386 Ubuntu Ubuntu Linux 12.04 LTS amd64 Ubuntu Ubuntu Linux 10.04 sparc Ubuntu Ubuntu Linux 10.04 powerpc Ubuntu Ubuntu Linux 10.04 i386 Ubuntu Ubuntu Linux 10.04 ARM Ubuntu Ubuntu Linux 10.04 amd64 |
| Not Vulnerable: | |
Discussion
elfutils '/libelf/elf_begin.c' Directory Traversal Vulnerability
elfutils is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input.
Remote attackers can use a specially crafted request with directory-traversal sequences ('../') to retrieve arbitrary files in the context of the application. Information obtained could aid in further attacks.
elfutils is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input.
Remote attackers can use a specially crafted request with directory-traversal sequences ('../') to retrieve arbitrary files in the context of the application. Information obtained could aid in further attacks.
Solution / Fix
elfutils '/libelf/elf_begin.c' Directory Traversal Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
elfutils '/libelf/elf_begin.c' Directory Traversal Vulnerability
References:
References: