[Forgot Password]
Login  Register Subscribe

30481

 
 

423868

 
 

256288

 
 

909

 
 

199146

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-2142-1 dpkg -- directory traversal

ID: oval:org.secpod.oval:def:600544Date: (C)2011-07-05   (M)2022-10-10
Class: PATCHFamily: unix




Jakub Wilk discovered that the dpkg-source component of dpkg, the Debian package management system, doesn"t correctly handle paths in patches of source packages, which could make it traverse directories. Raphaël Hertzog additionally discovered that symbolic links in the .pc directory are followed, which could make it traverse directories too. Both issues only affect source packages using the "3.0 quilt" format at unpack-time.

Platform:
Debian 5.0
Product:
dpkg
Reference:
DSA-2142-1
CVE-2010-1679
CVE    1
CVE-2010-1679
CPE    1
cpe:/o:debian:debian_linux:5.0

© SecPod Technologies