1 |
type: security |
2 |
subject: Updated p7zip package fixes security vulnerability |
3 |
CVE: |
4 |
- CVE-2015-1038 |
5 |
src: |
6 |
4: |
7 |
core: |
8 |
- p7zip-9.20.1-4.1.mga4 |
9 |
5: |
10 |
core: |
11 |
- p7zip-9.20.1-6.1.mga5 |
12 |
description: | |
13 |
Alexander Cherepanov discovered that p7zip is susceptible to a directory |
14 |
traversal vulnerability. While extracting an archive, it will extract |
15 |
symlinks and then follow them if they are referenced in further entries. |
16 |
This can be exploited by a rogue archive to write files outside the |
17 |
current directory (CVE-2015-1038). |
18 |
references: |
19 |
- https://bugs.mageia.org/show_bug.cgi?id=16122 |
20 |
- https://www.debian.org/security/2015/dsa-3289 |
21 |
ID: MGASA-2015-0252 |