Advisories ยป MGASA-2015-0018

Updated gcab packages fix CVE-2015-0552

Publication date: 09 Jan 2015
Modification date: 09 Jan 2015
Type: security
Affected Mageia releases : 4
CVE: CVE-2015-0552

Description

Updated gcab packages fix security vulnerability:

Jakub Wilk reported a directory traversal vulnerability due to gcab not
filtering leading slashes from paths in CAB files (CVE-2015-0552).
                

References

SRPMS

4/core