CVE-2014-3127: Path Traversal
dpkg 1.15.9 on Debian squeeze introduces support for the "C-style encoded filenames" feature without recognizing that the squeeze patch program lacks this feature, which triggers an interaction error that allows remote attackers to conduct directory traversal attacks and modify files outside of the intended directories via a crafted source package. NOTE: this can be considered a release engineering problem in the effort to fix CVE-2014-0471.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-3127?
CVE-2014-3127 is classified as a high-severity vulnerability due to its potential for causing directory traversal attacks.
How do I fix CVE-2014-3127?
To fix CVE-2014-3127, upgrade to a patched version of dpkg, specifically versions 1.16.0 or later.
What are the implications of exploiting CVE-2014-3127?
Exploiting CVE-2014-3127 can allow remote attackers to modify files outside of the intended directory structure.
Which versions of dpkg are affected by CVE-2014-3127?
Affected versions of dpkg include 1.15.9 and possibly earlier versions up to 1.16.4, which lack the security fixes.
Is CVE-2014-3127 still a threat today?
CVE-2014-3127 remains a threat for systems that have not been updated to secure versions of dpkg.