SUSE-SU-2015:0434-1
Dashboard / Vulnerabilities / SUSE-SU-2015:0434-1
SUSE-SU-2015:0434-1
Summary: Security update for elfutils
Details: elfutils has been updated to fix one security issue: * CVE-2014-9447: Directory traversal vulnerability in the read_long_names function in libelf/elf_begin.c in elfutils 0.152 and 0.161 allowed remote attackers to write to arbitrary files to the root directory via a / (slash) in a crafted archive, as demonstrated using the ar program (bnc#911662). Security Issues: * CVE-2014-9447 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9447>
References: https://www.suse.com/support/update/announcement/2015/suse-su-20150434-1/, https://bugzilla.suse.com/911662, https://www.suse.com/security/cve/CVE-2014-9447
