PT-2014-5151 · Debian+1 · Dpkg+1
Raphael Geissert
·
Publicado
2014-05-13
·
Atualizado
2014-06-24
·
CVE-2014-3227
CVSS v2.0
6.4
Média
| Vetor | AV:N/AC:L/Au:N/C:N/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
dpkg versions 1.15.9, 1.16.x through 1.16.13, and 1.17.x through 1.17.8
Description
The issue arises from dpkg's expectation that the patch program supports "C-style encoded filenames", which can lead to an interaction error in environments where the patch program does not comply with this requirement. This error can be exploited by remote attackers to conduct directory traversal attacks, allowing them to modify files outside the intended directories by using a crafted source package.
Recommendations
For dpkg version 1.15.9, update to a version that does not rely on the "C-style encoded filenames" feature for security.
For dpkg versions 1.16.x through 1.16.13, update to version 1.16.14 or later.
For dpkg versions 1.17.x through 1.17.8, update to version 1.17.9 or later.
Correção
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Dpkg