Fiche vulnérabilité
CVE-2022-4515 : faille élevée exuberant ctags project exuberant ctags (CVSS 7.8)
Description
A flaw was found in Exuberant Ctags in the way it handles the "-o" option. This option specifies the tag filename. A crafted tag filename specified in the command line or in the configuration file results in arbitrary command execution because the externalSortTags() in sort.c calls the system(3) function in an unsafe way.
En bref
- Sévérité
- Élevée (CVSS 7.8)
- Vecteur CVSS
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Exploitation active
- Non signalée par la CISA
- Publication
- 20 déc. 2022
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- exuberant ctags project exuberant ctags
- debian debian linux