CVE-2014-0471: Path Traversal
Directory traversal vulnerability in the unpacking functionality in dpkg before 1.15.9, 1.16.x before 1.16.13, and 1.17.x before 1.17.8 allows remote attackers to write arbitrary files via a crafted source package, related to "C-style filename quoting."
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/dpkgto a version that resolves this vulnerability.Fixed in 1.20.13Fixed in 1.20.10Fixed in 1.21.22Fixed in 1.22.18
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0471?
CVE-2014-0471 is considered a medium severity vulnerability due to its potential to allow remote attackers to write arbitrary files.
How do I fix CVE-2014-0471?
To fix CVE-2014-0471, upgrade dpkg to version 1.15.9 or later.
What systems are affected by CVE-2014-0471?
CVE-2014-0471 affects dpkg versions prior to 1.15.9, including some versions in Debian and Ubuntu.
What type of vulnerability is CVE-2014-0471?
CVE-2014-0471 is a directory traversal vulnerability that affects the unpacking functionality of dpkg.
Can CVE-2014-0471 be exploited remotely?
Yes, CVE-2014-0471 can be exploited remotely through crafted source packages.