Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2017-8283

Опубликовано: 26 апр. 2017
Источник: ubuntu
Приоритет: negligible
EPSS Низкий
CVSS2: 7.5
CVSS3: 9.8

Описание

dpkg-source in dpkg 1.3.0 through 1.18.23 is able to use a non-GNU patch program and does not offer a protection mechanism for blank-indented diff hunks, which allows remote attackers to conduct directory traversal attacks via a crafted Debian source package, as demonstrated by use of dpkg-source on NetBSD.

РелизСтатусПримечание
artful

ignored

end of life
bionic

not-affected

1.18.24ubuntu1
cosmic

ignored

end of life
devel

not-affected

disco

ignored

end of life
eoan

ignored

end of life
esm-infra-legacy/trusty

not-affected

esm-infra/bionic

not-affected

1.18.24ubuntu1
esm-infra/focal

not-affected

esm-infra/xenial

not-affected

Показывать по

EPSS

Процентиль: 77%
0.01076
Низкий

7.5 High

CVSS2

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
nvd
почти 9 лет назад

dpkg-source in dpkg 1.3.0 through 1.18.23 is able to use a non-GNU patch program and does not offer a protection mechanism for blank-indented diff hunks, which allows remote attackers to conduct directory traversal attacks via a crafted Debian source package, as demonstrated by use of dpkg-source on NetBSD.

CVSS3: 9.8
debian
почти 9 лет назад

dpkg-source in dpkg 1.3.0 through 1.18.23 is able to use a non-GNU pat ...

CVSS3: 9.8
github
больше 3 лет назад

dpkg-source in dpkg 1.3.0 through 1.18.23 is able to use a non-GNU patch program and does not offer a protection mechanism for blank-indented diff hunks, which allows remote attackers to conduct directory traversal attacks via a crafted Debian source package, as demonstrated by use of dpkg-source on NetBSD.

EPSS

Процентиль: 77%
0.01076
Низкий

7.5 High

CVSS2

9.8 Critical

CVSS3