CVE-2014-1833: Path Traversal
Directory traversal vulnerability in uupdate in devscripts 2.14.1 allows remote attackers to modify arbitrary files via a crafted .orig.tar file, related to a symlink.
Other sources
Jakub Wilk reported a directory traversal flaw in uupdate that "can trick uupdate into patching files outside the source package directory". A patch is not yet available.
Further details and a reproducer are available from http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=737160
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-1833?
The severity of CVE-2014-1833 is considered moderate due to its directory traversal nature that allows unauthorized file modifications.
How do I fix CVE-2014-1833?
To fix CVE-2014-1833, you should update the devscripts package to version 2.14.2 or later.
What type of vulnerability is CVE-2014-1833?
CVE-2014-1833 is classified as a directory traversal vulnerability affecting the uupdate tool in devscripts.
Which software is affected by CVE-2014-1833?
CVE-2014-1833 specifically affects the devscripts version 2.14.1.
Who reported the CVE-2014-1833 vulnerability?
The CVE-2014-1833 vulnerability was reported by Jakub Wilk.