Candidate: CVE-2015-8747 PublicDate: 2016-02-03 18:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8747 Description: The multifilesystem storage backend in Radicale before 1.1 allows remote attackers to read or write to arbitrary files via a crafted component name. Ubuntu-Description: Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=809920 Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N [10.0 CRITICAL] Patches_radicale: upstream_radicale: released (1.1.1-1) precise_radicale: ignored (reached end-of-life) precise/esm_radicale: DNE (precise was needed) trusty_radicale: ignored (reached end-of-life) trusty/esm_radicale: DNE (trusty was needed) vivid_radicale: released (0.9-1+deb8u1build0.15.04.1) vivid/stable-phone-overlay_radicale: DNE vivid/ubuntu-core_radicale: DNE wily_radicale: ignored (reached end-of-life) xenial_radicale: not-affected (1.1.1-1) yakkety_radicale: ignored (reached end-of-life) zesty_radicale: ignored (reached end-of-life) artful_radicale: ignored (reached end-of-life) bionic_radicale: not-affected (1.1.1-1) cosmic_radicale: not-affected (1.1.1-1) disco_radicale: not-affected (1.1.1-1) devel_radicale: not-affected (1.1.1-1)