Show filters
6 Total Results
Displaying 1-6 of 6
Sort by:
Attacker Value
Unknown

CVE-2017-8283

Disclosure Date: April 26, 2017 (last updated November 26, 2024)
dpkg-source in dpkg 1.3.0 through 1.18.23 is able to use a non-GNU patch program and does not offer a protection mechanism for blank-indented diff hunks, which allows remote attackers to conduct directory traversal attacks via a crafted Debian source package, as demonstrated by use of dpkg-source on NetBSD.
0
Attacker Value
Unknown

CVE-2014-0471

Disclosure Date: April 30, 2014 (last updated October 05, 2023)
Directory traversal vulnerability in the unpacking functionality in dpkg before 1.15.9, 1.16.x before 1.16.13, and 1.17.x before 1.17.8 allows remote attackers to write arbitrary files via a crafted source package, related to "C-style filename quoting."
0
Attacker Value
Unknown

CVE-2011-0402

Disclosure Date: January 11, 2011 (last updated October 04, 2023)
dpkg-source in dpkg before 1.14.31 and 1.15.x allows user-assisted remote attackers to modify arbitrary files via a symlink attack on unspecified files in the .pc directory.
0
Attacker Value
Unknown

CVE-2010-1679

Disclosure Date: January 11, 2011 (last updated October 04, 2023)
Directory traversal vulnerability in dpkg-source in dpkg before 1.14.31 and 1.15.x allows user-assisted remote attackers to modify arbitrary files via directory traversal sequences in a patch for a source-format 3.0 package.
0
Attacker Value
Unknown

CVE-2004-2768

Disclosure Date: June 08, 2010 (last updated October 04, 2023)
dpkg 1.9.21 does not properly reset the metadata of a file during replacement of the file in a package upgrade, which might allow local users to gain privileges by creating a hard link to a vulnerable (1) setuid file, (2) setgid file, or (3) device, a related issue to CVE-2010-2059.
0
Attacker Value
Unknown

CVE-2010-0396

Disclosure Date: March 15, 2010 (last updated October 04, 2023)
Directory traversal vulnerability in the dpkg-source component in dpkg before 1.14.29 allows remote attackers to modify arbitrary files via a crafted Debian source archive.
0