VulnerabilityModified
CVE-2014-0471
Directory traversal vulnerability in the unpacking functionality in dpkg before 1.15.9, 1.16.x before 1.16.13, and 1.17.x before 1.17.8 allows remote attackers to write arbitrary files via a crafted source package, related to "C-style filename quoting."
MEDIUM 5.0EPSS 2.88%
Does this matter?
Lower severity and a low EPSS score (2.88%). Track it; it rarely justifies an emergency change on its own.
Description
Directory traversal vulnerability in the unpacking functionality in dpkg before 1.15.9, 1.16.x before 1.16.13, and 1.17.x before 1.17.8 allows remote attackers to write arbitrary files via a crafted source package, related to "C-style filename quoting."
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
- EPSS
- 2.88% probability · 86th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- debian/dpkg · canonical/ubuntu linux
- Source
- security@debian.org
References
- http://www.debian.org/security/2014/dsa-2915Vendor Advisory
- http://www.securityfocus.com/bid/67106
- http://www.ubuntu.com/usn/USN-2183-1Vendor Advisory
- http://www.debian.org/security/2014/dsa-2915Vendor Advisory
- http://www.securityfocus.com/bid/67106
- http://www.ubuntu.com/usn/USN-2183-1Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.