SphinxSearch in Sphinx Technologies Sphinx through 3.1.1 allows directory traversal (in conjunction with CVE-2019-14511) because the mysql client can be used for CALL SNIPPETS and load_file operations on a full pathname (e.g., a file in the /etc directory). NOTE: this is unrelated to CMUSphinx.
Advisories
Source ID Title
Debian DLA Debian DLA DLA-2882-1 sphinxsearch security update
Debian DSA Debian DSA DSA-5036-1 sphinxsearch security update
EUVD EUVD EUVD-2020-21432 SphinxSearch in Sphinx Technologies Sphinx through 3.1.1 allows directory traversal (in conjunction with CVE-2019-14511) because the mysql client can be used for CALL SNIPPETS and load_file operations on a full pathname (e.g., a file in the /etc directory). NOTE: this is unrelated to CMUSphinx.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-04T16:48:01.488Z

Reserved: 2020-11-24T00:00:00

Link: CVE-2020-29050

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-01-10T14:10:16.077

Modified: 2024-11-21T05:23:35.540

Link: CVE-2020-29050

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses