[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250053

 
 

909

 
 

195940

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS2-2023-2343 --- ctags

ID: oval:org.secpod.oval:def:1701936Date: (C)2023-11-24   (M)2023-11-24
Class: PATCHFamily: unix




A flaw was found in Exuberant Ctags in the way it handles the "-o" option. This option specifies the tag filename. A crafted tag filename specified in the command line or in the configuration file results in arbitrary command execution because the externalSortTags in sort.c calls the system function in an unsafe way

Platform:
Amazon Linux 2
Product:
ctags
Reference:
ALAS2-2023-2343
CVE-2022-4515
CVE    1
CVE-2022-4515
CPE    2
cpe:/a:ctags:ctags
cpe:/o:amazon:linux:2

© SecPod Technologies