Your submission was sent successfully! Close

You have successfully unsubscribed! Close

CVE-2014-3864

Published: 30 May 2014

Directory traversal vulnerability in dpkg-source in dpkg-dev 1.3.0 allows remote attackers to modify files outside of the intended directories via a crafted source package that lacks a --- header line.

Priority

Medium

Status

Package Release Status
dpkg
Launchpad, Ubuntu, Debian
lucid
Released (1.15.5.6ubuntu4.9)
precise
Released (1.16.1.2ubuntu7.5)
saucy
Released (1.16.12ubuntu1.3)
trusty
Released (1.17.5ubuntu5.3)
upstream
Released (1.17.10)
Patches:
upstream: http://anonscm.debian.org/gitweb/?p=dpkg/dpkg.git;a=commitdiff;h=5348cbc