CVE-2015-0857: Command Injection
Published May 6, 2016
·Updated
Cool Projects TarDiff allows remote attackers to execute arbitrary commands via shell metacharacters in the name of a (1) tar file or (2) file within a tar file.
Affected Software
2 affected components
Tardiff Project Tardiff
Debian Debian Linux=8.0
Event History
May 6, 2016
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-0857?
CVE-2015-0857 has a moderate severity level due to the potential for remote command execution.
2
How do I fix CVE-2015-0857?
To fix CVE-2015-0857, update to the latest version of TarDiff or apply the security patches provided by your distribution.
3
What type of attack does CVE-2015-0857 enable?
CVE-2015-0857 enables remote attackers to execute arbitrary commands on the system.
4
Which software is affected by CVE-2015-0857?
CVE-2015-0857 affects TarDiff and Debian GNU/Linux 8.0.
5
Is there a workaround for CVE-2015-0857?
There is no official workaround for CVE-2015-0857; upgrading is the recommended solution.