|
|
| |
|
| |
dpkg: path traversal
| Package(s): | dpkg |
CVE #(s): | CVE-2010-0396
|
| Created: | March 11, 2010 |
Updated: | March 22, 2010 |
| Description: |
From the Debian advisory:
William Grant discovered that the dpkg-source component of dpkg, the
low-level infrastructure for handling the installation and removal of
Debian software packages, is vulnerable to path traversal attacks.
A specially crafted Debian source package can lead to file modification
outside of the destination directory when extracting the package content.
|
| Alerts: |
|
( Log in to post comments)
|
|
|