High severity7.8NVD Advisory· Published Dec 20, 2022· Updated Jun 17, 2026
CVE-2022-4515
CVE-2022-4515
Description
A flaw was found in Exuberant Ctags in the way it handles the "-o" option. This option specifies the tag filename. A crafted tag filename specified in the command line or in the configuration file results in arbitrary command execution because the externalSortTags() in sort.c calls the system(3) function in an unsafe way.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
30- cpe:2.3:a:exuberant_ctags_project:exuberant_ctags:*:*:*:*:*:*:*:*
- Exuberant Ctags/Exuberant Ctagsdescription
- osv-coords26 versionspkg:rpm/almalinux/ctagspkg:rpm/almalinux/ctags-etagspkg:rpm/opensuse/ctags&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/ctags&distro=openSUSE%20Tumbleweedpkg:rpm/suse/ctags&distro=SUSE%20Enterprise%20Storage%206pkg:rpm/suse/ctags&distro=SUSE%20Enterprise%20Storage%207pkg:rpm/suse/ctags&distro=SUSE%20Enterprise%20Storage%207.1pkg:rpm/suse/ctags&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-LTSSpkg:rpm/suse/ctags&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP2-LTSSpkg:rpm/suse/ctags&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP3-ESPOSpkg:rpm/suse/ctags&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP3-LTSSpkg:rpm/suse/ctags&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Development%20Tools%2015%20SP4pkg:rpm/suse/ctags&distro=SUSE%20Linux%20Enterprise%20Real%20Time%2015%20SP3pkg:rpm/suse/ctags&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-BCLpkg:rpm/suse/ctags&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP4-LTSSpkg:rpm/suse/ctags&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5pkg:rpm/suse/ctags&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP1-LTSSpkg:rpm/suse/ctags&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP2-LTSSpkg:rpm/suse/ctags&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP3-LTSSpkg:rpm/suse/ctags&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP4pkg:rpm/suse/ctags&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5pkg:rpm/suse/ctags&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP1pkg:rpm/suse/ctags&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP2pkg:rpm/suse/ctags&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP3pkg:rpm/suse/ctags&distro=SUSE%20OpenStack%20Cloud%209pkg:rpm/suse/ctags&distro=SUSE%20OpenStack%20Cloud%20Crowbar%209
< 5.8-23.el8+ 25 more
- (no CPE)range: < 5.8-23.el8
- (no CPE)range: < 5.8-23.el8
- (no CPE)range: < 5.8-150000.3.3.1
- (no CPE)range: < 5.8-12.1
- (no CPE)range: < 5.8-150000.3.3.1
- (no CPE)range: < 5.8-150000.3.3.1
- (no CPE)range: < 5.8-150000.3.3.1
- (no CPE)range: < 5.8-150000.3.3.1
- (no CPE)range: < 5.8-150000.3.3.1
- (no CPE)range: < 5.8-150000.3.3.1
- (no CPE)range: < 5.8-150000.3.3.1
- (no CPE)range: < 5.8-150000.3.3.1
- (no CPE)range: < 5.8-150000.3.3.1
- (no CPE)range: < 5.8-8.3.1
- (no CPE)range: < 5.8-8.3.1
- (no CPE)range: < 5.8-8.3.1
- (no CPE)range: < 5.8-150000.3.3.1
- (no CPE)range: < 5.8-150000.3.3.1
- (no CPE)range: < 5.8-150000.3.3.1
- (no CPE)range: < 5.8-8.3.1
- (no CPE)range: < 5.8-8.3.1
- (no CPE)range: < 5.8-150000.3.3.1
- (no CPE)range: < 5.8-150000.3.3.1
- (no CPE)range: < 5.8-150000.3.3.1
- (no CPE)range: < 5.8-8.3.1
- (no CPE)range: < 5.8-8.3.1
Patches
Vulnerability mechanics
References
2- sourceforge.net/p/ctags/code/HEAD/tree/tags/ctags-5.8/sort.cnvdExploitThird Party Advisory
- lists.debian.org/debian-lts-announce/2022/12/msg00040.htmlnvdMailing ListThird Party Advisory
News mentions
0No linked articles in our index yet.