Back

HIGH

EmbedThis GoAhead 3.0.0 through 3.4.1 does not properly handle path segments starting with a

Published Mar 31, 2015

Description

EmbedThis GoAhead 3.0.0 through 3.4.1 does not properly handle path segments starting with a . (dot), which allows remote attackers to conduct directory traversal attacks, cause a denial of service (heap-based buffer overflow and crash), or possibly execute arbitrary code via a crafted URI.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Mar 31, 2015
Updated Aug 6, 2024
Reserved Mar 23, 2015
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a