Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2014-3127


dpkg 1.15.9 on Debian squeeze introduces support for the "C-style encoded filenames" feature without recognizing that the squeeze patch program lacks this feature, which triggers an interaction error that allows remote attackers to conduct directory traversal attacks and modify files outside of the intended directories via a crafted source package. NOTE: this can be considered a release engineering problem in the effort to fix CVE-2014-0471.


Published

2014-05-14T00:55:10.400

Last Modified

2025-04-12T10:46:40.837

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 7.1 (HIGH)

CVSSv2 Vector

AV:N/AC:H/Au:N/C:N/I:C/A:C

  • Access Vector: NETWORK
  • Access Complexity: HIGH
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

4.9

Impact Score

9.2

Weaknesses
  • Type: Primary
    CWE-22

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application debian dpkg 1.16.0 Yes
Application debian dpkg 1.16.0.1 Yes
Application debian dpkg 1.16.0.2 Yes
Application debian dpkg 1.16.0.3 Yes
Application debian dpkg 1.16.1 Yes
Application debian dpkg 1.16.1.1 Yes
Application debian dpkg 1.16.1.2 Yes
Application debian dpkg 1.16.2 Yes
Application debian dpkg 1.16.3 Yes
Application debian dpkg 1.16.4 Yes
Application debian dpkg 1.16.4.1 Yes
Application debian dpkg 1.16.4.2 Yes
Application debian dpkg 1.16.4.3 Yes
Application debian dpkg 1.16.5 Yes
Application debian dpkg 1.16.6 Yes
Application debian dpkg 1.16.7 Yes
Application debian dpkg 1.16.8 Yes
Application debian dpkg 1.16.9 Yes
Application debian dpkg 1.16.10 Yes
Application debian dpkg 1.16.11 Yes
Application debian dpkg 1.16.12 Yes
Application debian dpkg 1.17.0 Yes
Application debian dpkg 1.17.1 Yes
Application debian dpkg 1.17.2 Yes
Application debian dpkg 1.17.3 Yes
Application debian dpkg 1.17.4 Yes
Application debian dpkg 1.17.5 Yes
Application debian dpkg 1.17.6 Yes
Application debian dpkg 1.17.7 Yes
Application debian dpkg 1.17.8 Yes
Application debian dpkg 1.15.0 Yes
Application debian dpkg 1.15.1 Yes
Application debian dpkg 1.15.2 Yes
Application debian dpkg 1.15.3 Yes
Application debian dpkg 1.15.3.1 Yes
Application debian dpkg 1.15.4 Yes
Application debian dpkg 1.15.4.1 Yes
Application debian dpkg 1.15.5 Yes
Application debian dpkg 1.15.5.1 Yes
Application debian dpkg 1.15.5.2 Yes
Application debian dpkg 1.15.5.3 Yes
Application debian dpkg 1.15.5.4 Yes
Application debian dpkg 1.15.5.5 Yes
Application debian dpkg 1.15.5.6 Yes
Application debian dpkg 1.15.6 Yes
Application debian dpkg 1.15.6.1 Yes
Application debian dpkg 1.15.7 Yes
Application debian dpkg 1.15.7.1 Yes
Application debian dpkg 1.15.7.2 Yes
Application debian dpkg 1.15.8 Yes
Application debian dpkg 1.15.8.1 Yes
Application debian dpkg 1.15.8.2 Yes
Application debian dpkg 1.15.8.3 Yes
Application debian dpkg 1.15.8.4 Yes
Application debian dpkg 1.15.8.5 Yes
Application debian dpkg 1.15.8.6 Yes
Application debian dpkg 1.15.8.7 Yes
Application debian dpkg 1.15.8.8 Yes
Application debian dpkg 1.15.8.9 Yes
Application debian dpkg 1.15.8.10 Yes
Application debian dpkg 1.15.8.11 Yes
Application debian dpkg 1.15.8.12 Yes
Application debian dpkg 1.15.8.13 Yes
Application debian dpkg 1.15.9 Yes

References