PT-2014-4320 · Debian+2 · Devscripts+2

CVE-2014-1833

·

Publicado

2014-02-05

·

Atualizado

2024-07-30

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions devscripts version 2.14.1
Description A directory traversal issue in uupdate in devscripts allows remote attackers to modify arbitrary files via a crafted .orig.tar file, related to a symlink.
Recommendations For devscripts version 2.14.1, update to a version that fixes this issue to prevent remote attackers from modifying arbitrary files.

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-1833
SUSE-SU-2024:2621-1
SUSE-SU-2024_2621-1
USN-2649-1

Produtos afetados

Suse
Ubuntu
Devscripts