MGASA-2023-0003

Source
https://advisories.mageia.org/MGASA-2023-0003.html
Import Source
https://advisories.mageia.org/MGASA-2023-0003.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2023-0003
Related
Published
2023-01-13T17:37:09Z
Modified
2023-01-13T16:41:20Z
Summary
Updated ctags packages fix security vulnerability
Details

A flaw was found in Exuberant Ctags in the way it handles the "-o" option. This option specifies the tag filename. A crafted tag filename specified in the command line or in the configuration file results in arbitrary command execution because the externalSortTags() in sort.c calls the system(3) function in an unsafe way. (CVE-2022-4515)

References
Credits

Affected packages

Mageia:8 / ctags

Package

Name
ctags
Purl
pkg:rpm/mageia/ctags?distro=mageia-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.8-15.1.mga8

Ecosystem specific

{
    "section": "core"
}