A flaw was found in Exuberant Ctags in the way it handles the "-o" option. This option specifies the tag filename. A crafted tag filename specified in the command line or in the configuration file results in arbitrary command execution because the externalSortTags() in sort.c calls the system(3) function in an unsafe way.
Metrics
Affected Vendors & Products
References
History
Mon, 14 Apr 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: redhat
Published: 2022-12-20T00:00:00.000Z
Updated: 2025-04-14T18:14:57.235Z
Reserved: 2022-12-15T00:00:00.000Z
Link: CVE-2022-4515

Updated: 2024-08-03T01:41:45.615Z

Status : Modified
Published: 2022-12-20T19:15:25.190
Modified: 2025-04-14T19:15:35.290
Link: CVE-2022-4515
