A flaw was found in Exuberant Ctags in the way it handles the "-o" option. This option specifies the tag filename. A crafted tag filename specified in the command line or in the configuration file results in arbitrary command execution because the externalSortTags() in sort.c calls the system(3) function in an unsafe way.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: redhat
Published: 2022-12-20T00:00:00
Updated: 2024-08-03T01:41:45.615Z
Reserved: 2022-12-15T00:00:00
Link: CVE-2022-4515

No data.

Status : Modified
Published: 2022-12-20T19:15:25.190
Modified: 2024-11-21T07:35:25.033
Link: CVE-2022-4515
