CVE-2014-3864: Path Traversal
Published May 30, 2014
·Updated
Directory traversal vulnerability in dpkg-source in dpkg-dev 1.3.0 allows remote attackers to modify files outside of the intended directories via a crafted source package that lacks a --- header line.
Affected Software
1 affected component
Debian Dpkg-dev=1.3.0
Event History
May 30, 2014
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Data Sourced
via NVD·06:55 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2014-3864?
CVE-2014-3864 is classified as a medium severity vulnerability.
2
How do I fix CVE-2014-3864?
To fix CVE-2014-3864, upgrade dpkg-dev to a version later than 1.3.0 that includes the necessary patches.
3
Who is affected by CVE-2014-3864?
CVE-2014-3864 affects users of dpkg-dev version 1.3.0 on Debian systems.
4
What does CVE-2014-3864 allow an attacker to do?
CVE-2014-3864 allows an attacker to perform directory traversal, potentially modifying files outside intended directories.
5
Is CVE-2014-3864 a common vulnerability?
CVE-2014-3864 is not widely known but poses significant risks for systems using the affected version.