LWN.net Logo

dpkg: path traversal

Package(s):dpkg CVE #(s):CVE-2010-0396
Created:March 11, 2010 Updated:March 22, 2010
Description: From the Debian advisory:

William Grant discovered that the dpkg-source component of dpkg, the low-level infrastructure for handling the installation and removal of Debian software packages, is vulnerable to path traversal attacks. A specially crafted Debian source package can lead to file modification outside of the destination directory when extracting the package content.

Alerts:
Fedora FEDORA-2010-4344 2010-03-13
Fedora FEDORA-2010-4371 2010-03-13
Ubuntu USN-909-1 2010-03-11
Debian DSA-2011-1 2010-03-10

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds