{"affected":[],"aliases":[],"details":"\nelfutils has been updated to fix one security issue:\n\n    * CVE-2014-9447: Directory traversal vulnerability in the\n      read_long_names function in libelf/elf_begin.c in elfutils 0.152 and\n      0.161 allowed remote attackers to write to arbitrary files to the\n      root directory via a / (slash) in a crafted archive, as demonstrated\n      using the ar program (bnc#911662).\n\nSecurity Issues:\n\n    * CVE-2014-9447\n      <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9447>\n\n","id":"SUSE-SU-2015:0434-1","modified":"2015-02-18T18:35:01Z","published":"2015-02-18T18:35:01Z","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2015/suse-su-20150434-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/911662"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2014-9447"}],"related":["CVE-2014-9447"],"summary":"Security update for elfutils","upstream":["CVE-2014-9447"]}