CVE-2014-3127
Summary
| CVE | CVE-2014-3127 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-05-14 00:55:10 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | dpkg 1.15.9 on Debian squeeze introduces support for the "C-style encoded filenames" feature without recognizing that the squeeze patch program lacks this feature, which triggers an interaction error that allows remote attackers to conduct directory traversal attacks and modify files outside of the intended directories via a crafted source package. NOTE: this can be considered a release engineering problem in the effort to fix CVE-2014-0471. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
HighAuthentication
NoneConfidentiality
NoneIntegrity
CompleteAvailability
CompleteAV:N/AC:H/Au:N/C:N/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Debian | Dpkg | 1.15.0 | All | All | All |
| Application | Debian | Dpkg | 1.15.1 | All | All | All |
| Application | Debian | Dpkg | 1.15.2 | All | All | All |
| Application | Debian | Dpkg | 1.15.3 | All | All | All |
| Application | Debian | Dpkg | 1.15.3.1 | All | All | All |
| Application | Debian | Dpkg | 1.15.4 | All | All | All |
| Application | Debian | Dpkg | 1.15.4.1 | All | All | All |
| Application | Debian | Dpkg | 1.15.5 | All | All | All |
| Application | Debian | Dpkg | 1.15.5.1 | All | All | All |
| Application | Debian | Dpkg | 1.15.5.2 | All | All | All |
| Application | Debian | Dpkg | 1.15.5.3 | All | All | All |
| Application | Debian | Dpkg | 1.15.5.4 | All | All | All |
| Application | Debian | Dpkg | 1.15.5.5 | All | All | All |
| Application | Debian | Dpkg | 1.15.5.6 | All | All | All |
| Application | Debian | Dpkg | 1.15.6 | All | All | All |
| Application | Debian | Dpkg | 1.15.6.1 | All | All | All |
| Application | Debian | Dpkg | 1.15.7 | All | All | All |
| Application | Debian | Dpkg | 1.15.7.1 | All | All | All |
| Application | Debian | Dpkg | 1.15.7.2 | All | All | All |
| Application | Debian | Dpkg | 1.15.8 | All | All | All |
| Application | Debian | Dpkg | 1.15.8.1 | All | All | All |
| Application | Debian | Dpkg | 1.15.8.10 | All | All | All |
| Application | Debian | Dpkg | 1.15.8.11 | All | All | All |
| Application | Debian | Dpkg | 1.15.8.12 | All | All | All |
| Application | Debian | Dpkg | 1.15.8.13 | All | All | All |
| Application | Debian | Dpkg | 1.15.8.2 | All | All | All |
| Application | Debian | Dpkg | 1.15.8.3 | All | All | All |
| Application | Debian | Dpkg | 1.15.8.4 | All | All | All |
| Application | Debian | Dpkg | 1.15.8.5 | All | All | All |
| Application | Debian | Dpkg | 1.15.8.6 | All | All | All |
| Application | Debian | Dpkg | 1.15.8.7 | All | All | All |
| Application | Debian | Dpkg | 1.15.8.8 | All | All | All |
| Application | Debian | Dpkg | 1.15.8.9 | All | All | All |
| Application | Debian | Dpkg | 1.15.9 | All | All | All |
| Application | Debian | Dpkg | 1.16.0 | All | All | All |
| Application | Debian | Dpkg | 1.16.0.1 | All | All | All |
| Application | Debian | Dpkg | 1.16.0.2 | All | All | All |
| Application | Debian | Dpkg | 1.16.0.3 | All | All | All |
| Application | Debian | Dpkg | 1.16.1 | All | All | All |
| Application | Debian | Dpkg | 1.16.1.1 | All | All | All |
| Application | Debian | Dpkg | 1.16.1.2 | All | All | All |
| Application | Debian | Dpkg | 1.16.10 | All | All | All |
| Application | Debian | Dpkg | 1.16.11 | All | All | All |
| Application | Debian | Dpkg | 1.16.12 | All | All | All |
| Application | Debian | Dpkg | 1.16.2 | All | All | All |
| Application | Debian | Dpkg | 1.16.3 | All | All | All |
| Application | Debian | Dpkg | 1.16.4 | All | All | All |
| Application | Debian | Dpkg | 1.16.4.1 | All | All | All |
| Application | Debian | Dpkg | 1.16.4.2 | All | All | All |
| Application | Debian | Dpkg | 1.16.4.3 | All | All | All |
| Application | Debian | Dpkg | 1.16.5 | All | All | All |
| Application | Debian | Dpkg | 1.16.6 | All | All | All |
| Application | Debian | Dpkg | 1.16.7 | All | All | All |
| Application | Debian | Dpkg | 1.16.8 | All | All | All |
| Application | Debian | Dpkg | 1.16.9 | All | All | All |
| Application | Debian | Dpkg | 1.17.0 | All | All | All |
| Application | Debian | Dpkg | 1.17.1 | All | All | All |
| Application | Debian | Dpkg | 1.17.2 | All | All | All |
| Application | Debian | Dpkg | 1.17.3 | All | All | All |
| Application | Debian | Dpkg | 1.17.4 | All | All | All |
| Application | Debian | Dpkg | 1.17.5 | All | All | All |
| Application | Debian | Dpkg | 1.17.6 | All | All | All |
| Application | Debian | Dpkg | 1.17.7 | All | All | All |
| Application | Debian | Dpkg | 1.17.8 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| oss-sec: CVE request: directory traversal in DSA-2915-1-patched dpkg in Debian squeeze | af854a3a-2127-422b-91ae-364da2661108 | seclists.org | |
| dpkg CVE-2014-3127 Incomplete Fix Local Directory Traversal Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| 404 Not Found | af854a3a-2127-422b-91ae-364da2661108 | metadata.ftp-master.debian.org | |
| #746306 - dpkg: CVE-2014-0471 fix introduces the vulnerability into squeeze - Debian Bug report logs | af854a3a-2127-422b-91ae-364da2661108 | bugs.debian.org | |
| oss-sec: Re: CVE request: directory traversal in DSA-2915-1-patched dpkg in Debian squeeze | af854a3a-2127-422b-91ae-364da2661108 | seclists.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.