The changelog command in Apt prior to 1.0.9.2 allows local users to write to arbitrary files via a symlink attack on the changelog file.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
debian apt 1.0.9 |
||
debian advanced package tool |
||
debian apt 0.9.7.9 |
||
debian advanced package tool 1.0.8 |