Back to search
CVE-2020-29050
Published: Jan 7, 2022
Modified: Aug 4, 2024
PUBLISHED
Description
SphinxSearch in Sphinx Technologies Sphinx through 3.1.1 allows directory traversal (in conjunction with CVE-2019-14511) because the mysql client can be used for CALL SNIPPETS and load_file operations on a full pathname (e.g., a file in the /etc directory). NOTE: this is unrelated to CMUSphinx.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
https://security-tracker.debian.org/tracker/CVE-2020-29050
x_refsource_MISC
[debian-lts-announce] 20220117 [SECURITY] [DLA 2882-1] sphinxsearch security update
mailing-list
x_refsource_MLIST
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now