CVE-2014-3864

NameCVE-2014-3864
DescriptionDirectory traversal vulnerability in dpkg-source in dpkg-dev 1.3.0 allows remote attackers to modify files outside of the intended directories via a crafted source package that lacks a --- header line.
SourceCVE (at NVD; LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, GitHub code/issues, web search, more)
ReferencesDSA-2953-1
NVD severitymedium (attack range: remote)
Debian Bugs746498

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
dpkg (PTS)wheezy (security), wheezy1.16.17fixed
jessie (security), jessie1.17.26fixed
stretch, sid1.18.4fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
dpkgsource(unstable)1.17.10medium746498
dpkgsourcesqueeze1.15.11mediumDSA-2953-1
dpkgsourcewheezy1.16.15mediumDSA-2953-1

Search for package or bug name: Reporting problems