CVE-2015-0552: Gnome Gcab

Medium severity, CVSS 6.4. EPSS: 2.8% chance of exploitation in the next 30 days.

Directory traversal vulnerability in the gcab_folder_extract function in libgcab/gcab-folder.c in gcab 0.4 allows remote attackers to write to arbitrary files via crafted path in a CAB file, as demonstrated by "\tmp\moo."

Affected products

  • Gnome Gcab: version 0.4 only
  • Opensuse Opensuse: version 13.1 only; version 13.2 only

Published 2015-01-15. Last modified 2026-06-17.