{"id":"SUSE-SU-2015:0434-1","summary":"Security update for elfutils","details":"\nelfutils has been updated to fix one security issue:\n\n    * CVE-2014-9447: Directory traversal vulnerability in the\n      read_long_names function in libelf/elf_begin.c in elfutils 0.152 and\n      0.161 allowed remote attackers to write to arbitrary files to the\n      root directory via a / (slash) in a crafted archive, as demonstrated\n      using the ar program (bnc#911662).\n\nSecurity Issues:\n\n    * CVE-2014-9447\n      \u003chttp://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9447\u003e\n\n","modified":"2026-02-04T04:18:08.884772Z","published":"2015-02-18T18:35:01Z","related":["CVE-2014-9447"],"upstream":["CVE-2014-9447"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2015/suse-su-20150434-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/911662"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2014-9447"}],"schema_version":"1.7.3"}