PT-2014-5151 · Debian+1 · Dpkg+1

Raphael Geissert

·

Published

2014-05-13

·

Updated

2014-06-24

·

CVE-2014-3227

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions dpkg versions 1.15.9, 1.16.x through 1.16.13, and 1.17.x through 1.17.8
Description The issue arises from dpkg's expectation that the patch program supports "C-style encoded filenames", which can lead to an interaction error in environments where the patch program does not comply with this requirement. This error can be exploited by remote attackers to conduct directory traversal attacks, allowing them to modify files outside the intended directories by using a crafted source package.
Recommendations For dpkg version 1.15.9, update to a version that does not rely on the "C-style encoded filenames" feature for security. For dpkg versions 1.16.x through 1.16.13, update to version 1.16.14 or later. For dpkg versions 1.17.x through 1.17.8, update to version 1.17.9 or later.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2014-1627
CVE-2014-3227
DSA-2915-2

Affected Products

Alt Linux
Dpkg