| |
Vulnerability CVE-2014-9983
Published: 2017-06-04 Modified: 2017-06-05
Description: |
Directory Traversal exists in RAR 4.x and 5.x because an unpack operation follows any symlinks, including symlinks contained in the archive. This allows remote attackers to write to arbitrary files via a crafted archive. |
CVSS2 => (AV:N/AC:M/Au:N/C:N/I:P/A:N)
CVSS Base Score |
Impact Subscore |
Exploitability Subscore |
4.3/10 |
2.9/10 |
8.6/10 |
Exploit range |
Attack complexity |
Authentication |
Remote |
Medium |
No required |
Confidentiality impact |
Integrity impact |
Availability impact |
None |
Partial |
None |
References: |
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=774172
|
|
|
closedb();
?>
Copyright 2024, cxsecurity.com
|
|
|