CVE-2015-0556: Medium severity arj archiver vulnerability
Published Jan 2, 2015
·Updated
Open-source ARJ archiver 3.10.22 allows remote attackers to conduct directory traversal attacks via a symlink attack in an ARJ archive.
Affected Software
6 affected componentsFixes available
debian/arj<=3.10.22-9, <=3.10.22-10, <=3.10.22-12
3.10.22-133.10.22-10+deb7u13.10.22-9+deb6u1
debian/arj
3.10.22-243.10.22-263.10.22-27
Arj Software Arj Archiver<=3.10.22
Fedoraproject Fedora=20
Fedoraproject Fedora=21
Fedoraproject Fedora=22
Event History
Apr 8, 2015
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-0556?
CVE-2015-0556 has a medium severity rating due to its potential for directory traversal attacks.
2
How do I fix CVE-2015-0556?
To fix CVE-2015-0556, update to a patched version of the ARJ archiver that is 3.10.22-24 or newer.
3
What is affected by CVE-2015-0556?
CVE-2015-0556 affects the ARJ archiver versions up to 3.10.22 and the Fedora operating system versions 20 to 22.
4
Can CVE-2015-0556 be exploited remotely?
Yes, CVE-2015-0556 can be exploited remotely through crafted ARJ archives containing symlink attacks.
5
Who is responsible for addressing CVE-2015-0556?
The maintainer of the ARJ archiver, particularly on Debian and Fedora platforms, is responsible for addressing CVE-2015-0556.