PT-2014-5562 · Debian+1 · Dpkg-Dev+1

Guillem Jover

·

Published

2014-05-30

·

Updated

2017-12-29

·

CVE-2014-3865

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions dpkg-dev version 1.3.0
Description The issue allows remote attackers to modify files outside of the intended directories via a source package with a crafted Index: pseudo-header. This can be achieved in conjunction with either (1) missing --- and +++ header lines or (2) a +++ header line with a blank pathname.
Recommendations For dpkg-dev version 1.3.0, update to a version that fixes the directory traversal vulnerabilities to prevent remote attackers from modifying files outside the intended directories.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-3865
DSA-2953-1
MGASA-2014-0289
USN-2242-1

Affected Products

Ubuntu
Dpkg-Dev