[Forgot Password]
Login  Register Subscribe

30480

 
 

423868

 
 

253164

 
 

909

 
 

197077

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS2-2023-2343 --- ctags

ID: oval:org.secpod.oval:def:1701936Date: (C)2023-11-24   (M)2023-11-24
Class: PATCHFamily: unix




A flaw was found in Exuberant Ctags in the way it handles the "-o" option. This option specifies the tag filename. A crafted tag filename specified in the command line or in the configuration file results in arbitrary command execution because the externalSortTags in sort.c calls the system function in an unsafe way

Platform:
Amazon Linux 2
Product:
ctags
Reference:
ALAS2-2023-2343
CVE-2022-4515
CVE    1
CVE-2022-4515
CPE    2
cpe:/a:ctags:ctags
cpe:/o:amazon:linux:2

© SecPod Technologies