Candidate: CVE-2015-1191 PublicDate: 2015-01-21 18:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1191 https://github.com/madler/pigz/commit/fdad1406b3ec809f4954ff7cdf9e99eb18c2458f Description: Multiple directory traversal vulnerabilities in pigz 2.3.1 allow remote attackers to write to arbitrary files via a (1) full pathname or (2) .. (dot dot) in an archive. Ubuntu-Description: It was discovered that pigz was susceptible to a directory traversal vulnerability. If a user were tricked into opening a malicious archive, arbitrary files could be overwritten. Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=774978 Priority: medium Discovered-by: Assigned-to: mikesalvatore CVSS: Patches_pigz: upstream_pigz: not-affected (2.3.1-2) lucid_pigz: ignored (reached end-of-life) precise_pigz: ignored (reached end-of-life) precise/esm_pigz: DNE (precise was needs-triage) trusty_pigz: ignored (out of standard support) trusty/esm_pigz: released (2.3-2ubuntu0.1~esm1) utopic_pigz: ignored (reached end-of-life) vivid_pigz: ignored (reached end-of-life) vivid/stable-phone-overlay_pigz: DNE vivid/ubuntu-core_pigz: DNE wily_pigz: ignored (reached end-of-life) xenial_pigz: not-affected (2.3.1-2) yakkety_pigz: not-affected (2.3.1-2) zesty_pigz: not-affected artful_pigz: not-affected bionic_pigz: not-affected cosmic_pigz: not-affected disco_pigz: not-affected eoan_pigz: not-affected focal_pigz: not-affected groovy_pigz: not-affected hirsute_pigz: not-affected impish_pigz: not-affected jammy_pigz: not-affected devel_pigz: not-affected