CVE-2014-10073

NameCVE-2014-10073
DescriptionThe create_response function in server/server.c in Psensor before 1.1.4 allows Directory Traversal because it lacks a check for whether a file is under the webserver directory.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDLA-1361-1
Debian Bugs896195

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
psensor (PTS)bullseye1.1.5-1.3fixed
bookworm1.1.5-1.4fixed
sid, trixie1.2.1-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
psensorsourcewheezy0.6.2.17-2+deb7u1DLA-1361-1
psensorsourcejessie1.1.3-2+deb8u1
psensorsource(unstable)1.1.5-1low896195

Notes

http://git.wpitchoune.net/gitweb/?p=psensor.git;a=commitdiff;h=8b10426dcc0246c1712a99460dd470dcb1cc4d9c

Search for package or bug name: Reporting problems