Directory Traversal Vulnerability in Dpkg Utility on Debian
CVE-2014-3127

Currently unrated

Key Information:

Vendor
Debian
Status
Vendor
CVE Published:
14 May 2014

Summary

The vulnerability in Dpkg 1.15.9 on Debian squeeze allows remote attackers to exploit a flaw in the handling of C-style encoded filenames. As the patch program does not support this feature, it can lead to directory traversal attacks that permit unauthorized modification of files outside their intended directories when processing a specially crafted source package.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.