PT-2014-5151 · Debian+1 · Dpkg+1
Raphael Geissert
·
Published
2014-05-13
·
Updated
2014-06-24
·
CVE-2014-3227
CVSS v2.0
6.4
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
dpkg versions 1.15.9, 1.16.x through 1.16.13, and 1.17.x through 1.17.8
Description
The issue arises from dpkg's expectation that the patch program supports "C-style encoded filenames", which can lead to an interaction error in environments where the patch program does not comply with this requirement. This error can be exploited by remote attackers to conduct directory traversal attacks, allowing them to modify files outside the intended directories by using a crafted source package.
Recommendations
For dpkg version 1.15.9, update to a version that does not rely on the "C-style encoded filenames" feature for security.
For dpkg versions 1.16.x through 1.16.13, update to version 1.16.14 or later.
For dpkg versions 1.17.x through 1.17.8, update to version 1.17.9 or later.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Dpkg