First published: Thu Oct 02 2014(Updated: )
The changelog command in Apt before 1.0.9.2 allows local users to write to arbitrary files via a symlink attack on the changelog file.
Credit: security@debian.org
Affected Software | Affected Version | How to fix |
---|---|---|
Debian Advanced Package Tool | <=1.0.9.1 | |
Debian Advanced Package Tool | =1.0.8 | |
Debian Apt | =0.9.7.9-ubunto3 | |
Debian Apt | =0.9.7.9-ubunto4 | |
Debian Apt | =0.9.7.9-ubunto5 | |
Debian Apt | =1.0.9 | |
debian/apt | 2.2.4 2.6.1 2.9.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.