Summary
Jakub Wilk discovered that dpkg did not correctly parse C-style filename quoting, allowing for paths to be traversed when unpacking a source package - leading to the creation of files outside the directory of the source being unpacked.
The update to the stable distribution (wheezy) incorporates non-security changes that were targeted for the point release 7.5.
Solution
For the oldstable distribution (squeeze), this problem has been fixed in version 1.15.9.
For the stable distribution (wheezy), this problem has been fixed in version 1.16.13.
For the testing distribution (jessie), this problem will be fixed soon.
For the unstable distribution (sid), this problem will be fixed in version 1.17.8.
We recommend that you upgrade your dpkg packages.
Insight
This package provides the low-level infrastructure for handling the installation and removal of Debian software packages.
Affected
dpkg on Debian Linux
Detection
This check tests the installed software version using the apt package manager.
References
Updated on 2015-03-25
Severity
Classification
-
CVE CVE-2014-0471 -
CVSS Base Score: 5.0
AV:N/AC:L/Au:N/C:N/I:P/A:N
Related Vulnerabilities