Directory Traversal Vulnerability in Dpkg Utility on Debian
CVE-2014-3127

Currently unrated

Key Information:

Vendor

Debian

Status
Vendor
CVE Published:
14 May 2014

What is CVE-2014-3127?

The vulnerability in Dpkg 1.15.9 on Debian squeeze allows remote attackers to exploit a flaw in the handling of C-style encoded filenames. As the patch program does not support this feature, it can lead to directory traversal attacks that permit unauthorized modification of files outside their intended directories when processing a specially crafted source package.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.