CVE-2015-0552
gcab 0.4 - Path Traversal and Arbitrary File Write via CAB File Path
Title source: llmDescription
Directory traversal vulnerability in the gcab_folder_extract function in libgcab/gcab-folder.c in gcab 0.4 allows remote attackers to write to arbitrary files via crafted path in a CAB file, as demonstrated by "\tmp\moo."
References (5)
Core 5
Core References
Exploit x_refsource_confirm
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=774580
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/62310
Issue Tracking x_refsource_confirm
https://bugzilla.gnome.org/show_bug.cgi?id=742331
Mailing List mailing-list
x_refsource_mlist
http://www.openwall.com/lists/oss-security/2015/01/05/7
Mailing List vendor-advisory
x_refsource_suse
http://lists.opensuse.org/opensuse-updates/2015-01/msg00018.html
Scores
EPSS
0.0074
EPSS Percentile
73.1%
Details
CWE
CWE-22
Status
published
Products (3)
gnome/gcab
0.4
opensuse/opensuse
13.1
opensuse/opensuse
13.2
Published
Jan 15, 2015
Tracked Since
Feb 18, 2026