dpkg: path traversal
| Package(s): | dpkg | CVE #(s): | CVE-2010-0396 | ||||||||||||||||
| Created: | March 11, 2010 | Updated: | March 22, 2010 | ||||||||||||||||
| Description: | From the Debian advisory:
William Grant discovered that the dpkg-source component of dpkg, the low-level infrastructure for handling the installation and removal of Debian software packages, is vulnerable to path traversal attacks. A specially crafted Debian source package can lead to file modification outside of the destination directory when extracting the package content. | ||||||||||||||||||
| Alerts: |
| ||||||||||||||||||
