CVE-2015-1194: Pax Project Pax

Medium severity, CVSS 4.3. EPSS: 1.7% chance of exploitation in the next 30 days.

pax 1:20140703 allows remote attackers to write to arbitrary files via a symlink attack in an archive.

Affected products

Published 2015-01-21. Last modified 2026-06-17.