Search CVE reports
1 – 2 of 2 results
In the opam package before 2.5.2 for OCaml, the sandbox protection mechanism can be bypassed because symlinks are mishandled during use of .install files.
1 affected package
opam
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| opam | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
Some fixes available 5 of 7
In OCaml opam before 2.5.1, a .install field containing a destination filepath can use ../ to reach a parent directory.
1 affected package
opam
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| opam | Fixed | Fixed | Fixed | Fixed | Ignored |