6.8
CVSSv2

CVE-2010-1679

Published: 11/01/2011 Updated: 17/08/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Directory traversal vulnerability in dpkg-source in dpkg prior to 1.14.31 and 1.15.x allows user-assisted remote malicious users to modify arbitrary files via directory traversal sequences in a patch for a source-format 3.0 package.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

debian dpkg 1.14.16

debian dpkg 1.14.15

debian dpkg 1.14.18

debian dpkg 1.14.17

debian dpkg 1.14.16.6

debian dpkg 1.14.26

debian dpkg 1.14.23

debian dpkg 1.13.12

debian dpkg 1.13.11.1

debian dpkg 1.13.19

debian dpkg 1.13.22

debian dpkg 1.14.2

debian dpkg 1.14.3

debian dpkg 1.14.10

debian dpkg 1.14.11

debian dpkg 1.13.1

debian dpkg 1.13.0

debian dpkg 1.14.14

debian dpkg 1.14.13

debian dpkg 1.14.16.5

debian dpkg 1.14.22

debian dpkg 1.14.24

debian dpkg 1.14.27

debian dpkg 1.13.14

debian dpkg 1.13.13

debian dpkg 1.13.21

debian dpkg 1.13.23

debian dpkg 1.14.4

debian dpkg 1.14.5

debian dpkg 1.14.12

debian dpkg 1.14.28

debian dpkg 1.13.3

debian dpkg 1.13.2

debian dpkg 1.10.24

debian dpkg 1.10.23

debian dpkg 1.10.16

debian dpkg 1.10.17

debian dpkg 1.10.10

debian dpkg 1.10.9

debian dpkg 1.10.5

debian dpkg 1.9.20

debian dpkg 1.9.19

debian dpkg 1.14.16.2

debian dpkg 1.14.16.1

debian dpkg 1.14.19

debian dpkg 1.14.25

debian dpkg 1.13.11

debian dpkg 1.13.10

debian dpkg 1.13.18

debian dpkg 1.13.17

debian dpkg 1.13.20

debian dpkg 1.14.0

debian dpkg 1.14.1

debian dpkg 1.14.8

debian dpkg 1.14.9

debian dpkg 1.13.7

debian dpkg 1.13.6

debian dpkg 1.10.28

debian dpkg 1.10.27

debian dpkg 1.10.19

debian dpkg 1.10.20

debian dpkg 1.10.13

debian dpkg 1.10.6

debian dpkg 1.10.2

debian dpkg 1.10.1

debian dpkg 1.10.22

debian dpkg 1.10.21

debian dpkg 1.10.14

debian dpkg 1.10.15

debian dpkg 1.10.7

debian dpkg 1.10.8

debian dpkg 1.10

debian dpkg 1.9.21

debian dpkg 1.14.16.4

debian dpkg 1.14.16.3

debian dpkg 1.14.21

debian dpkg 1.14.20

debian dpkg 1.13.9

debian dpkg 1.13.8

debian dpkg 1.13.16

debian dpkg 1.13.15

debian dpkg 1.13.24

debian dpkg 1.13.25

debian dpkg 1.14.6

debian dpkg 1.14.7

debian dpkg 1.14.29

debian dpkg 1.13.5

debian dpkg 1.13.4

debian dpkg 1.10.26

debian dpkg 1.10.25

debian dpkg 1.10.18

debian dpkg 1.10.18.1

debian dpkg 1.10.11

debian dpkg 1.10.12

debian dpkg 1.10.4

debian dpkg 1.10.3

debian dpkg

debian dpkg 1.15.3.1

debian dpkg 1.15.4

debian dpkg 1.15.5

debian dpkg 1.15.5.6

debian dpkg 1.15.6

debian dpkg 1.15.8.2

debian dpkg 1.15.8.3

debian dpkg 1.15.0

debian dpkg 1.15.1

debian dpkg 1.15.5.3

debian dpkg 1.15.5.4

debian dpkg 1.15.7.1

debian dpkg 1.15.7.2

debian dpkg 1.15.8.6

debian dpkg 1.15.8.7

debian dpkg 1.15.2

debian dpkg 1.15.3

debian dpkg 1.15.4.1

debian dpkg 1.15.5.5

debian dpkg 1.15.8

debian dpkg 1.15.8.1

debian dpkg 1.15.8.8

debian dpkg 1.15.5.1

debian dpkg 1.15.5.2

debian dpkg 1.15.6.1

debian dpkg 1.15.7

debian dpkg 1.15.8.4

debian dpkg 1.15.8.5

Vendor Advisories

A malicious source package could write files outside the unpack directory ...
Jakub Wilk discovered that the dpkg-source component of dpkg, the Debian package management system, doesn't correctly handle paths in patches of source packages, which could make it traverse directories Raphaël Hertzog additionally discovered that symbolic links in the pc directory are followed, which could make it traverse directories too Both ...