CVE-2015-2304
libarchive - security update
EPSS 3.0%
Description
Absolute path traversal vulnerability in bsdcpio in libarchive 3.1.2 and earlier allows remote attackers to write to arbitrary files via a full pathname in an archive.
How to fix CVE-2015-2304
To remediate CVE-2015-2304, upgrade the affected package to a fixed version below.
- Debian/libarchive—upgrade to 3.1.2-11 or later
- Debian/libarchive—upgrade to 2.8.4.forreal-1+squeeze3 or later
- Debian/libarchive—upgrade to 3.0.4-3+wheezy1 or later
Is CVE-2015-2304 being exploited?
Low — EPSS is 3.0%, meaning exploitation activity has not been observed at scale.
Affected packages (3)
- from 0, < 3.1.2-11
- from 0, < 2.8.4.forreal-1+squeeze3
- from 0, < 3.0.4-3+wheezy1