suse · CVE-2014-9447

Quick triage

Priority: medium Published: 2021-05-30 13:24:44 UTC Updated: 2026-04-18 18:31:26 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2014-9447 severity moderate: SUSE including 415 source package names (0.9.1:elfutils-0.158-6.1, 0.9.1:libasm1-0.158-6.1, …), 816 product×package rows across 94 product lines (Container caasp/v4/default-http-backend, Container caasp/v4/dnsmasq-nanny, … (94 product lines)): Fixed 659, Known Affected 157.

Description:

Directory traversal vulnerability in the read_long_names function in libelf/elf_begin.c in elfutils 0.152 and 0.161 allows remote attackers to write to arbitrary files to the root directory via a / (slash) in a crafted archive, as demonstrated using the ar program.

cvelogic Threat Intelligence