ARJ CVE-2015-0557 Directory Traversal Vulnerability
BID:71895
Info
ARJ CVE-2015-0557 Directory Traversal Vulnerability
| Bugtraq ID: | 71895 |
| Class: | Input Validation Error |
| CVE: |
CVE-2015-0557 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 02 2015 12:00AM |
| Updated: | Dec 20 2016 12:08AM |
| Credit: | Jakub Wilk |
| Vulnerable: |
Mandriva Business Server 1 X86 64 Mandriva Business Server 1 Gentoo Linux Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 ARJ Software Inc. ARJ 3.10.22-12 ARJ Software Inc. ARJ 3.10.22-10 |
| Not Vulnerable: | |
Discussion
ARJ CVE-2015-0557 Directory Traversal Vulnerability
ARJ is prone to a directory-traversal vulnerability.
A remote attacker could exploit this issue using directory-traversal characters ('../') to access or read arbitrary files that contain sensitive information or to access files outside of the restricted directory to obtain sensitive information and perform other attacks.
ARJ 3.10.22-10 and 3.10.22-12 are vulnerable.
NOTE: This issue was previously covered in BID 71860 (ARJ CVE-2015-0556 Directory Traversal Vulnerability) but has been given its own record for better documentation.
ARJ is prone to a directory-traversal vulnerability.
A remote attacker could exploit this issue using directory-traversal characters ('../') to access or read arbitrary files that contain sensitive information or to access files outside of the restricted directory to obtain sensitive information and perform other attacks.
ARJ 3.10.22-10 and 3.10.22-12 are vulnerable.
NOTE: This issue was previously covered in BID 71860 (ARJ CVE-2015-0556 Directory Traversal Vulnerability) but has been given its own record for better documentation.
Exploit / POC
ARJ CVE-2015-0557 Directory Traversal Vulnerability
Attackers can use standard, readily available tools to exploit this issue.
Attackers can use standard, readily available tools to exploit this issue.
Solution / Fix
ARJ CVE-2015-0557 Directory Traversal Vulnerability
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Mandriva Business Server 1 X86 64
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Mandriva Business Server 1 X86 64
-
Mandriva arj-3.10.22-8.1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/
References
ARJ CVE-2015-0557 Directory Traversal Vulnerability
References:
References:
- Arj Home Page (arj)
- arj: directory traversal via //multiple/leading/slash (bugs.debian.org)