A flaw was found in Exuberant Ctags in the way it handles the "-o" option. This option specifies the tag filename. A crafted tag filename specified in the command line or in the configuration file results in arbitrary command execution because the externalSortTags() in sort.c calls the system(3) function in an unsafe way.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3254-1 | exuberant-ctags security update |
EUVD |
EUVD-2022-51855 | A flaw was found in Exuberant Ctags in the way it handles the "-o" option. This option specifies the tag filename. A crafted tag filename specified in the command line or in the configuration file results in arbitrary command execution because the externalSortTags() in sort.c calls the system(3) function in an unsafe way. |
Ubuntu USN |
USN-5820-1 | exuberant-ctags vulnerability |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 14 Apr 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2025-04-14T18:14:57.235Z
Reserved: 2022-12-15T00:00:00.000Z
Link: CVE-2022-4515
Updated: 2024-08-03T01:41:45.615Z
Status : Modified
Published: 2022-12-20T19:15:25.190
Modified: 2025-04-14T19:15:35.290
Link: CVE-2022-4515
OpenCVE Enrichment
No data.
Debian DLA
EUVD
Ubuntu USN