Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2014-3127

Overview

Vulnerability Score 7.1 7.1
CVE Id CVE-2014-3127
Last Modified 05 Jun 2014 12:31:40
Published 13 May 2014 08:55:10
Confidentiality Impact NONE NONE
Integrity Impact COMPLETE COMPLETE
Availability Impact COMPLETE COMPLETE
Access Vector NETWORK
Access Complexity HIGH
Authentication NONE

CVE-2014-3127

Summary

dpkg 1.15.9 on Debian squeeze introduces support for the "C-style encoded filenames" feature without recognizing that the squeeze patch program lacks this feature, which triggers an interaction error that allows remote attackers to conduct directory traversal attacks and modify files outside of the intended directories via a crafted source package. NOTE: this can be considered a release engineering problem in the effort to fix CVE-2014-0471.

Vulnerable Systems

Application

  • Debian Dpkg 1.15.0

  • Debian Dpkg 1.15.1

  • Debian Dpkg 1.15.2

  • Debian Dpkg 1.15.3

  • Debian Dpkg 1.15.3.1

  • Debian Dpkg 1.15.4

  • Debian Dpkg 1.15.4.1

  • Debian Dpkg 1.15.5

  • Debian Dpkg 1.15.5.1

  • Debian Dpkg 1.15.5.2

  • Debian Dpkg 1.15.5.3

  • Debian Dpkg 1.15.5.4

  • Debian Dpkg 1.15.5.5

  • Debian Dpkg 1.15.5.6

  • Debian Dpkg 1.15.6

  • Debian Dpkg 1.15.6.1

  • Debian Dpkg 1.15.7

  • Debian Dpkg 1.15.7.1

  • Debian Dpkg 1.15.7.2

  • Debian Dpkg 1.15.8

  • Debian Dpkg 1.15.8.1

  • Debian Dpkg 1.15.8.10

  • Debian Dpkg 1.15.8.11

  • Debian Dpkg 1.15.8.12

  • Debian Dpkg 1.15.8.13

  • Debian Dpkg 1.15.8.2

  • Debian Dpkg 1.15.8.3

  • Debian Dpkg 1.15.8.4

  • Debian Dpkg 1.15.8.5

  • Debian Dpkg 1.15.8.6

  • Debian Dpkg 1.15.8.7

  • Debian Dpkg 1.15.8.8

  • Debian Dpkg 1.15.8.9

  • Debian Dpkg 1.15.9

  • Debian Dpkg 1.16.0

  • Debian Dpkg 1.16.0.1

  • Debian Dpkg 1.16.0.2

  • Debian Dpkg 1.16.0.3

  • Debian Dpkg 1.16.1

  • Debian Dpkg 1.16.1.1

  • Debian Dpkg 1.16.1.2

  • Debian Dpkg 1.16.10

  • Debian Dpkg 1.16.11

  • Debian Dpkg 1.16.12

  • Debian Dpkg 1.16.2

  • Debian Dpkg 1.16.3

  • Debian Dpkg 1.16.4

  • Debian Dpkg 1.16.4.1

  • Debian Dpkg 1.16.4.2

  • Debian Dpkg 1.16.4.3

  • Debian Dpkg 1.16.5

  • Debian Dpkg 1.16.6

  • Debian Dpkg 1.16.7

  • Debian Dpkg 1.16.8

  • Debian Dpkg 1.16.9

  • Debian Dpkg 1.17.0

  • Debian Dpkg 1.17.1

  • Debian Dpkg 1.17.2

  • Debian Dpkg 1.17.3

  • Debian Dpkg 1.17.4

  • Debian Dpkg 1.17.5

  • Debian Dpkg 1.17.6

  • Debian Dpkg 1.17.7

  • Debian Dpkg 1.17.8


References

CONFIRM - https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=746306

BID - 67181

MLIST - [oss-security] 20140501 Re: CVE request: directory traversal in DSA-2915-1-patched dpkg in Debian squeeze

MLIST - [oss-security] 20140429 CVE request: directory traversal in DSA-2915-1-patched dpkg in Debian squeeze

CONFIRM - http://metadata.ftp-master.debian.org/changelogs//main/d/dpkg/dpkg_1.15.10_changelog


Last Updated: 27 May 2016 11:05:16