SB2011011108 - Multiple vulnerabilities in dpkg



SB2011011108 - Multiple vulnerabilities in dpkg

Published: January 11, 2011 Updated: December 19, 2022

Security Bulletin ID SB2011011108
Severity
Medium
Patch available
YES
Number of vulnerabilities 2
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 2 secuirty vulnerabilities.


1) Link following (CVE-ID: CVE-2011-0402)

The vulnerability allows a remote attacker to overwrite arbitrary files on the system.

dpkg-source in dpkg before 1.14.31 and 1.15.x allows user-assisted remote attackers to modify arbitrary files via a symlink attack on unspecified files in the .pc directory.


2) Path traversal (CVE-ID: CVE-2010-1679)

The vulnerability allows a remote attacker to perform directory traversal attacks.

The vulnerability exists due to input validation error when processing directory traversal sequences. A remote attacker can trick the victim to install a specially crafted source package and overwrite arbitrary files on the system.


Remediation

Install update from vendor's website.