CVE-2015-0556
arj - security update
EPSS 3.8%
Description
Open-source ARJ archiver 3.10.22 allows remote attackers to conduct directory traversal attacks via a symlink attack in an ARJ archive.
How to fix CVE-2015-0556
To remediate CVE-2015-0556, upgrade the affected package to a fixed version below.
- Debian/arj—upgrade to 3.10.22-13 or later
- Debian/arj—upgrade to 3.10.22-9+deb6u1 or later
- Debian/arj—upgrade to 3.10.22-10+deb7u1 or later
Is CVE-2015-0556 being exploited?
Low — EPSS is 3.8%, meaning exploitation activity has not been observed at scale.
Affected packages (3)
- from 0, < 3.10.22-13
- from 0, < 3.10.22-9+deb6u1
- from 0, < 3.10.22-10+deb7u1