CVE-2011-0725: Path Traversal
Published Feb 23, 2011
·Updated
Absolute path traversal vulnerability in the org.debian.apt.UpdateCachePartially method in worker.py in Aptdaemon 0.40 in Ubuntu 10.10 and 11.04 allows local users to read arbitrary files via a full pathname in the sourceslist argument, related to the D-Bus interface.
Affected Software
3 affected components
Sebastian Heinlein Aptdaemon=0.40
Canonical Ubuntu Linux=10.10
Canonical Ubuntu Linux=11.04
Event History
Feb 23, 2011
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Data Sourced
07:00 PM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2011-0725?
CVE-2011-0725 is classified as a medium severity vulnerability.
2
How do I fix CVE-2011-0725?
To fix CVE-2011-0725, upgrade Aptdaemon to version 0.41 or later.
3
Who is affected by CVE-2011-0725?
CVE-2011-0725 affects local users of Aptdaemon 0.40 on Ubuntu 10.10 and 11.04.
4
What type of vulnerability is CVE-2011-0725?
CVE-2011-0725 is an absolute path traversal vulnerability.
5
What method is vulnerable in CVE-2011-0725?
The vulnerability in CVE-2011-0725 is found in the org.debian.apt.UpdateCachePartially method.