製品・ソフトウェアに関する情報
dpkg の dpkg-source におけるディレクトリトラバーサルの脆弱性
Title dpkg の dpkg-source におけるディレクトリトラバーサルの脆弱性
Summary

dpkg の dpkg-source には、ディレクトリトラバーサルの脆弱性が存在します。

Possible impacts 攻撃者により、source-format 3.0 パッケージ用のパッチのディレクトリトラバーサルシーケンスを介して、任意のファイルを変更される可能性があります。
Solution

ベンダより正式な対策が公開されています。ベンダ情報を参照して適切な対策を実施してください。

Publication Date Jan. 6, 2011, midnight
Registration Date March 27, 2012, 6:42 p.m.
Last Update Dec. 2, 2014, 5:44 p.m.
CVSS2.0 : 警告
Score 6.8
Vector AV:N/AC:M/Au:N/C:P/I:P/A:P
Affected System
Debian
dpkg 1.14.31 未満および 1.15.x
CVE (情報セキュリティ 共通脆弱性識別子)
CWE (共通脆弱性タイプ一覧)
ベンダー情報
Change Log
No Changed Details Date of change
0 [2012年03月27日]
  掲載
[2014年12月02日]
  ベンダ情報:オラクル (Multiple vulnerabilities in GNU patch utility) を追加
Feb. 17, 2018, 10:37 a.m.

NVD Vulnerability Information
CVE-2010-1679
Summary

Directory traversal vulnerability in dpkg-source in dpkg before 1.14.31 and 1.15.x allows user-assisted remote attackers to modify arbitrary files via directory traversal sequences in a patch for a source-format 3.0 package.

Publication Date Jan. 11, 2011, noon
Registration Date Jan. 29, 2021, 11 a.m.
Last Update Nov. 21, 2024, 10:14 a.m.
Affected software configurations
Configuration1 or higher or less more than less than
cpe:2.3:a:debian:dpkg:1.10.5:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.13.20:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.10.6:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.14.4:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.14.12:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.9.20:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.13.9:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.14.23:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.14.16.6:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.13.11:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.14.18:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.14.21:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.10:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.10.15:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.14.16.4:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.10.1:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.13.12:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.10.4:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.10.23:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.14.7:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.10.8:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.10.18.1:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.14.0:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.13.13:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.9.21:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.14.17:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.14.20:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.10.21:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.13.14:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.10.22:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.14.14:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.14.19:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.13.22:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.10.3:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.13.21:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:*:*:*:*:*:*:*:* 1.14.30
cpe:2.3:a:debian:dpkg:1.13.4:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.10.18:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.13.23:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.14.28:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.10.12:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.13.17:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.14.5:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.13.6:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.13.7:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.10.28:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.13.16:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.10.17:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.14.29:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.14.15:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.10.14:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.13.0:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.14.8:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.14.3:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.14.11:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.14.26:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.14.16.1:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.13.3:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.14.6:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.13.11.1:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.10.11:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.10.27:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.13.15:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.14.24:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.13.18:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.14.16.2:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.13.24:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.14.9:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.9.19:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.14.27:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.13.8:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.10.24:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.13.1:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.10.10:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.13.5:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.13.25:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.14.16.5:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.13.10:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.10.26:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.10.2:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.14.16:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.10.9:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.14.22:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.13.19:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.13.2:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.10.13:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.14.1:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.10.16:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.14.10:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.14.25:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.10.7:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.10.20:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.10.19:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.14.2:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.14.13:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.14.16.3:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.10.25:*:*:*:*:*:*:*
Configuration2 or higher or less more than less than
cpe:2.3:a:debian:dpkg:1.15.5.5:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.15.8.4:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.15.5.2:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.15.3.1:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.15.4.1:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.15.6:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.15.8.1:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.15.5:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.15.8.7:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.15.6.1:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.15.8.2:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.15.8.5:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.15.8.8:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.15.8.3:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.15.7:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.15.0:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.15.2:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.15.5.4:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.15.5.1:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.15.3:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.15.8:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.15.7.1:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.15.1:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.15.8.6:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.15.5.6:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.15.7.2:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.15.4:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:1.15.5.3:*:*:*:*:*:*:*
Related information, measures and tools
Common Vulnerabilities List