Back

HIGH

ctags: arbitrary command execution via a tag file with a crafted filename

Published Dec 20, 2022

Description

A flaw was found in Exuberant Ctags in the way it handles the "-o" option. This option specifies the tag filename. A crafted tag filename specified in the command line or in the configuration file results in arbitrary command execution because the externalSortTags() in sort.c calls the system(3) function in an unsafe way.

Affected products

Remediation

Red Hat statement

Exuberant Ctags is not shipped in Red Hat Enterprise Linux 9, therefore it's not affected.

Red Hat mitigation

The --options=NONE command line option will disable the automatic reading of any configuration file, including the .ctags configuration file from the current directory. However, this option will prevent ctags of reading the specific configuration provided by a project via a version control system repository.

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Dec 20, 2022
Updated Apr 14, 2025
Reserved Dec 15, 2022
CISA Vulnrichment
Updated Apr 14, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Dec 19, 2022
ENISA EUVD
Assigner redhat
Published Dec 20, 2022
Updated Apr 14, 2025
Exploited since n/a
EUVD-2022-51855