CVE-2015-1589
Publication date 23 February 2015
Last updated 24 July 2024
Ubuntu priority
Description
Directory traversal vulnerability in arCHMage 0.2.4 allows remote attackers to write to arbitrary files via a .. (dot dot) in a CHM file.
From the Ubuntu Security Team
It was discovered that the arCHMage allows remote attackers to write to arbitrary files via a special crafted file. An attacker could use this vulnerability to cause a DoS or possibly execute arbitrary code.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| archmage | ||
| 18.04 LTS bionic |
Not affected
|
|
| 16.04 LTS xenial |
Not affected
|
|
| 14.04 LTS trusty |
Fixed 1:0.2.4-4build0.14.04.1
|
|