SB2017042607 - Path traversal in packages.debian dpkg



SB2017042607 - Path traversal in packages.debian dpkg

Published: April 26, 2017 Updated: August 8, 2020

Security Bulletin ID SB2017042607
Severity
High
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Path traversal (CVE-ID: CVE-2017-8283)

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

dpkg-source in dpkg 1.3.0 through 1.18.23 is able to use a non-GNU patch program and does not offer a protection mechanism for blank-indented diff hunks, which allows remote attackers to conduct directory traversal attacks via a crafted Debian source package, as demonstrated by use of dpkg-source on NetBSD.


Remediation

Install update from vendor's website.