PT-2014-4320 · Debian+2 · Devscripts+2

Published

2014-02-05

·

Updated

2024-07-30

·

CVE-2014-1833

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions devscripts version 2.14.1
Description A directory traversal issue in uupdate in devscripts allows remote attackers to modify arbitrary files via a crafted .orig.tar file, related to a symlink.
Recommendations For devscripts version 2.14.1, update to a version that fixes this issue to prevent remote attackers from modifying arbitrary files.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2014-1833
SUSE-SU-2024:2621-1
SUSE-SU-2024_2621-1
USN-2649-1

Affected Products

Suse
Ubuntu
Devscripts