The IBM Notes Traveler Companion application 1.0 and 1.1 before 201411010515 for Window Phone, as distributed in IBM Notes Traveler 9.0.1, does not properly restrict the number of executions of the automatic configuration option, which makes it easier for remote attackers to capture credentials by conducting a phishing attack involving an encrypted e-mail message.
Jakub Wilk discovered that unace, an utility to extract, test and view
.ace archives, contained an integer overflow leading to a buffer
overflow. If a user or automated system were tricked into processing a
specially crafted ace archive, an attacker could cause a denial of
service (application crash) or, possibly, execute arbitrary code.
Resolved Bugs 1193952 – CVE-2015-2060 cabextract: directory traversal with UTF-8 symbols in filenames 1193956 – cabextract: directory traversal with UTF-8 symbols in filenames [epel-all]<br Security fix for directory traversal with UTF-8 symbols in filenames. Fixed in upstream version 1.5.
Resolved Bugs 1193952 – CVE-2015-2060 cabextract: directory traversal with UTF-8 symbols in filenames 1193956 – cabextract: directory traversal with UTF-8 symbols in filenames [epel-all]<br Security fix for directory traversal with UTF-8 symbols in filenames. Fixed in upstream version 1.5.