[Forgot Password]
Login  Register Subscribe

30481

 
 

423868

 
 

255227

 
 

909

 
 

198741

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2014-3127Date: (C)2014-05-15   (M)2023-12-22


dpkg 1.15.9 on Debian squeeze introduces support for the "C-style encoded filenames" feature without recognizing that the squeeze patch program lacks this feature, which triggers an interaction error that allows remote attackers to conduct directory traversal attacks and modify files outside of the intended directories via a crafted source package. NOTE: this can be considered a release engineering problem in the effort to fix CVE-2014-0471.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 7.1
Exploit Score: 4.9
Impact Score: 9.2
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: HIGH
Authentication: NONE
Confidentiality: NONE
Integrity: COMPLETE
Availability: COMPLETE
  
Reference:
BID-67181
http://seclists.org/oss-sec/2014/q2/191
http://seclists.org/oss-sec/2014/q2/227
http://metadata.ftp-master.debian.org/changelogs//main/d/dpkg/dpkg_1.15.10_changelog
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=746306

CPE    35
cpe:/a:debian:dpkg:1.16.10
cpe:/a:debian:dpkg:1.16.11
cpe:/a:debian:dpkg:1.16.12
cpe:/a:debian:dpkg:1.17.8
...
CWE    1
CWE-22

© SecPod Technologies