5
CVSSv2

CVE-2014-1833

Published: 05/02/2014 Updated: 03/01/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

Directory traversal vulnerability in uupdate in devscripts 2.14.1 allows remote malicious users to modify arbitrary files via a crafted .orig.tar file, related to a symlink.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

devscripts devel team devscripts 2.14.1

Vendor Advisories

Debian Bug report logs - #737160 uupdate: CVE-2014-1833: symlink directory traversal Package: devscripts; Maintainer for devscripts is Devscripts Maintainers <devscripts@packagesdebianorg>; Source for devscripts is src:devscripts (PTS, buildd, popcon) Reported by: Jakub Wilk <jwilk@debianorg> Date: Thu, 30 Jan 201 ...
devscripts could be made to overwrite files ...