CVE-2015-2304
EPSS 3.0%libarchive - security update
Published: 3/15/2015Modified: 4/28/2026
Description
Absolute path traversal vulnerability in bsdcpio in libarchive 3.1.2 and earlier allows remote attackers to write to arbitrary files via a full pathname in an archive.
Affected packages (3)
- Debian/libarchivefrom 0, < 3.1.2-11
- Debian/libarchivefrom 0, < 2.8.4.forreal-1+squeeze3
- Debian/libarchivefrom 0, < 3.0.4-3+wheezy1