CVE-2015-0557: Arj Software Arj Archiver

Medium severity, CVSS 5.8. EPSS: 3.3% chance of exploitation in the next 30 days.

Open-source ARJ archiver 3.10.22 does not properly remove leading slashes from paths, which allows remote attackers to conduct absolute path traversal attacks and write to arbitrary files via multiple leading slashes in a path in an ARJ archive.

Affected products

  • Arj Software Arj Archiver: up to and including 3.10.22
  • Fedoraproject Fedora: version 20 only; version 21 only; version 22 only

Published 2015-04-08. Last modified 2026-06-17.