Oval Definition:oval:org.mitre.oval:def:12905
Revision Date:2014-06-23Version:22
Title:DSA-2142-1 dpkg -- directory traversal
Description:Jakub Wilk discovered that the dpkg-source component of dpkg, the Debian package management system, doesn't correctly handle paths in patches of source packages, which could make it traverse directories. Raphaël Hertzog additionally discovered that symbolic links in the .pc directory are followed, which could make it traverse directories too. Both issues only affect source packages using the "3.0 quilt" format at unpack-time.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2010-1679
DSA-2142-1
Platform(s):Debian GNU/Linux 5.0
Product(s):dpkg
Definition Synopsis
  • Debian GNU/Linux 5.0 is installed
  • AND Installed architecture is all
  • AND dpkg DPKG is earlier than 1.14.31
  • BACK