Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Date: Sun, 25 May 2014 11:31:51 +0200
From: Raphael Geissert <geissert@...ian.org>
To: Open Source Security <oss-security@...ts.openwall.com>
Cc: guillem@...ian.org
Subject: CVE request: another path traversal in dpkg-source during unpack

Hi,

Another path traversal was discovered[1] in dpkg-source, related to the 
unpacking of source packages with specially-crafted patches.
While waiting for the original reporter's PoC/more information, Guillem 
Jover (dpkg maintainer) independently re-discovered the issue, and a second 
one.
This second issue has now been publicly reported as [2] to ease the 
assignment of CVE id(s) given the combination of private and not-very-
specific public information.

Both issues are independent of the version of the patch tool.

While figuring out whether one or two ids should be requested (at least from 
our POV), it appears that we can say that [2] is a superset of [1] - this is 
based on the minimal fixes needed to fix either vulnerability: the fix for [1] 
does not fix [2], but the fix for [2] does fix [1].

Could a CVE id be assigned please?

CC'ing Guillem for any complimentary information.

Thanks in advance.

[1] https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=746498
[2] https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=749183

Cheers,
-- 
Raphael Geissert - Debian Developer
www.debian.org - get.debian.net

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.