← Back

CVE-2022-4515

nvd nist
Published: Dec 20, 2022Modified: Apr 14, 2025

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

A flaw was found in Exuberant Ctags in the way it handles the "-o" option. This option specifies the tag filename. A crafted tag filename specified in the command line or in the configuration file results in arbitrary command execution because the externalSortTags() in sort.c calls the system(3) function in an unsafe way.

Affected (2)

Exuberant Ctags
1 product
Debian Linux
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
All versions
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 10.0

References (4)

Source: secalert@redhat.com
Mailing ListThird Party Advisory
Source: secalert@redhat.com
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory

Timeline

No history available yet.