A flaw was found in Exuberant Ctags in the way it handles the "-o" option. This option specifies the tag filename. A crafted tag filename specified in the command line or in the configuration file results in arbitrary command execution because the externalSortTags() in sort.c calls the system(3) function in an unsafe way.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | alma-upgrade-ctagsalma-upgrade-ctags-etags | May 23, 2023 | Dec 20, 2022 | |
| Amazon Linux Ami 2 | amazon-linux-ami-2-upgrade-ctagsamazon-linux-ami-2-upgrade-ctags-debuginfoamazon-linux-ami-2-upgrade-ctags-etags | Nov 16, 2023 | Dec 20, 2022 | |
| Amazon_linux | — | amazon-linux-upgrade-ctags | Apr 30, 2025 | Dec 20, 2022 |
| Centos_linux | — | centos-upgrade-ctagscentos-upgrade-ctags-debuginfocentos-upgrade-ctags-debugsource | May 17, 2023 | Dec 20, 2022 |
| Debian | debian-upgrade-exuberant-ctags | Jan 4, 2023 | Dec 20, 2022 | |
| Oracle_linux | — | oracle-linux-upgrade-ctagsoracle-linux-upgrade-ctags-etags | May 24, 2023 | Dec 19, 2022 |
| Redhat_linux | redhat-upgrade-ctagsredhat-upgrade-ctags-debuginforedhat-upgrade-ctags-debugsourceredhat-upgrade-ctags-etags | May 17, 2023 | Dec 20, 2022 | |
| Rocky_linux | rocky-upgrade-ctagsrocky-upgrade-ctags-debuginforocky-upgrade-ctags-debugsourcerocky-upgrade-ctags-etags | Jun 29, 2026 | Jun 25, 2026 | |
| Suse | — | suse-upgrade-ctags | Feb 2, 2023 | Dec 20, 2022 |
| Ubuntu | ubuntu-pro-upgrade-exuberant-ctagsubuntu-upgrade-exuberant-ctags | Jan 24, 2023 | Dec 20, 2022 | |
| Vmware Photon_os | vmware-photon_os_update_tdnf | Feb 9, 2026 | Dec 20, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub