CVE-2016-1244

NameCVE-2016-1244
DescriptionThe extractTree function in unADF allows remote attackers to execute arbitrary code via shell metacharacters in a directory name in an adf file.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDLA-3762-1, DLA-631-1, DSA-3676-1
Debian Bugs838248

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
unadf (PTS)buster0.7.11a-4vulnerable
buster (security)0.7.11a-4+deb11u1~deb10u1fixed
bullseye0.7.11a-4+deb11u1fixed
bookworm0.7.11a-5+deb12u1fixed
sid, trixie0.7.11a-6fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
unadfsourcewheezy0.7.11a-3+deb7u1DLA-631-1
unadfsourcejessie0.7.11a-3+deb8u1DSA-3676-1
unadfsourcebuster0.7.11a-4+deb11u1~deb10u1DLA-3762-1
unadfsourcebullseye0.7.11a-4+deb11u1
unadfsourcebookworm0.7.11a-5+deb12u1
unadfsource(unstable)0.7.11a-6838248

Notes

Fixed by: https://github.com/lclevy/ADFlib/commit/8e973d7b894552c3a3de0ccd2d1e9cb0b8e618dd
The changes between 0.7.11a-3 and 0.7.11a-4 did not include the upstream fix.

Search for package or bug name: Reporting problems