PT-2011-2588 · Debian · Aptdaemon
Sergey Nizovtsev
+1
·
Publicado
2011-02-23
·
Atualizado
2017-08-17
·
CVE-2011-0725
CVSS v2.0
4.9
Média
| Vetor | AV:L/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Aptdaemon version 0.40
Description
The issue is related to an absolute path traversal vulnerability in the org.debian.apt.UpdateCachePartially method in worker.py. This vulnerability allows local users to read arbitrary files via a full pathname in the
sources list argument, which is related to the D-Bus interface.Recommendations
For Aptdaemon version 0.40, consider restricting access to the
org.debian.apt.UpdateCachePartially method in the D-Bus interface until a patch is available. As a temporary workaround, avoid using the sources list argument with full pathnames in the affected API endpoint.Correção
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Aptdaemon