A flaw was found in Exuberant Ctags in the way it handles the "-o" option. This option specifies the tag filename. A crafted tag filename specified in the command line or in the configuration file results in arbitrary command execution because the externalSortTags() in sort.c calls the system(3) function in an unsafe way.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: redhat
Published: 2022-12-20T00:00:00
Updated: 2024-08-03T01:41:45.615Z
Reserved: 2022-12-15T00:00:00
Link: CVE-2022-4515
Vulnrichment
No data.
NVD
Status : Modified
Published: 2022-12-20T19:15:25.190
Modified: 2024-11-21T07:35:25.033
Link: CVE-2022-4515
Redhat