CVE-2014-0471
Publication date 28 April 2014
Last updated 24 July 2024
Ubuntu priority
Directory traversal vulnerability in the unpacking functionality in dpkg before 1.15.9, 1.16.x before 1.16.13, and 1.17.x before 1.17.8 allows remote attackers to write arbitrary files via a crafted source package, related to "C-style filename quoting."
Status
Package | Ubuntu Release | Status |
---|---|---|
dpkg | 14.04 LTS trusty |
Fixed 1.17.5ubuntu5.1
|
Notes
References
Related Ubuntu Security Notices (USN)
- USN-2183-1
- dpkg vulnerability
- 28 April 2014
- USN-2183-2
- dpkg vulnerability
- 1 May 2014