High severity7.5NVD Advisory· Published Jan 10, 2022· Updated Jun 17, 2026
CVE-2020-29050
CVE-2020-29050
Description
SphinxSearch in Sphinx Technologies Sphinx through 3.1.1 allows directory traversal (in conjunction with CVE-2019-14511) because the mysql client can be used for CALL SNIPPETS and load_file operations on a full pathname (e.g., a file in the /etc directory). NOTE: this is unrelated to CMUSphinx.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6- Sphinx Technologies/SphinxSearchdescription
- Range: <=3.1.1
- osv-coords2 versionspkg:rpm/opensuse/sphinx&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/sphinx&distro=openSUSE%20Leap%2015.3
< 2.2.11-lp154.3.3.1+ 1 more
- (no CPE)range: < 2.2.11-lp154.3.3.1
- (no CPE)range: < 2.2.11-lp153.2.3.1
Patches
Vulnerability mechanics
References
3- blog.wirhabenstil.de/2019/08/19/sphinxsearch-0-0-0-09306-cve-2019-14511/nvdExploitThird Party Advisory
- lists.debian.org/debian-lts-announce/2022/01/msg00009.htmlnvdMailing ListThird Party Advisory
- security-tracker.debian.org/tracker/CVE-2020-29050nvdThird Party Advisory
News mentions
0No linked articles in our index yet.