Candidate: CVE-2015-9275 PublicDate: 2019-01-07 18:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-9275 https://bugs.debian.org/774527 https://bugzilla.redhat.com/show_bug.cgi?id=1179142 Description: ARC 5.21q allows directory traversal via a full pathname in an archive file. Ubuntu-Description: Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=774527 Priority: low Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N [5.3 MEDIUM] Patches_arc: upstream_arc: released (5.21q-6) precise/esm_arc: DNE trusty_arc: ignored (reached end-of-life) trusty/esm_arc: DNE (trusty was needed) xenial_arc: ignored (end of standard support, was needed) bionic_arc: needed cosmic_arc: ignored (reached end-of-life) disco_arc: not-affected (5.21q-6) eoan_arc: not-affected (5.21q-6) focal_arc: not-affected (5.21q-6) groovy_arc: not-affected (5.21q-6) hirsute_arc: not-affected (5.21q-6) impish_arc: not-affected (5.21q-6) jammy_arc: not-affected (5.21q-6) devel_arc: not-affected (5.21q-6)