LWN.net Logo

cbrpager: execution of arbitrary code

Package(s):cbrpager CVE #(s):CVE-2008-2575
Created:June 17, 2008 Updated:June 18, 2008
Description: From the Gentoo advisory: Mamoru Tasaka discovered that filenames of the image archives are not properly sanitized before being passed to decompression utilities like unrar and unzip, which use the system() libc library call.
Alerts:
Gentoo 200806-05 2008-06-16

(Log in to post comments)

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds