CVE Database
/

CVE-2017-8283

Back to search

CVE-2017-8283

Published: Apr 26, 2017

Modified: Aug 5, 2024

PUBLISHED

Description

dpkg-source in dpkg 1.3.0 through 1.18.23 is able to use a non-GNU patch program and does not offer a protection mechanism for blank-indented diff hunks, which allows remote attackers to conduct directory traversal attacks via a crafted Debian source package, as demonstrated by use of dpkg-source on NetBSD.

VendorProductVersions

n/a

n/a

affected
n/a

References

98064
vdb-entry
x_refsource_BID

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now