CVE-2014-3227
Summary
| CVE | CVE-2014-3227 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-05-30 18:55:05 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | dpkg 1.15.9, 1.16.x before 1.16.14, and 1.17.x before 1.17.9 expect the patch program to be compliant with a need for the "C-style encoded filenames" feature, but is supported in environments with noncompliant patch programs, which triggers an interaction error that allows remote attackers to conduct directory traversal attacks and modify files outside of the intended directories via a crafted source package. NOTE: this vulnerability exists because of reliance on unrealistic constraints on the behavior of an external program. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:N/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Debian | Dpkg | 1.15.9 | All | All | All |
| Application | Debian | Dpkg | 1.16.0 | All | All | All |
| Application | Debian | Dpkg | 1.16.0.1 | All | All | All |
| Application | Debian | Dpkg | 1.16.0.2 | All | All | All |
| Application | Debian | Dpkg | 1.16.0.3 | All | All | All |
| Application | Debian | Dpkg | 1.16.1 | All | All | All |
| Application | Debian | Dpkg | 1.16.1.1 | All | All | All |
| Application | Debian | Dpkg | 1.16.1.2 | All | All | All |
| Application | Debian | Dpkg | 1.16.10 | All | All | All |
| Application | Debian | Dpkg | 1.16.11 | All | All | All |
| Application | Debian | Dpkg | 1.16.12 | All | All | All |
| Application | Debian | Dpkg | 1.16.2 | All | All | All |
| Application | Debian | Dpkg | 1.16.3 | All | All | All |
| Application | Debian | Dpkg | 1.16.4 | All | All | All |
| Application | Debian | Dpkg | 1.16.4.1 | All | All | All |
| Application | Debian | Dpkg | 1.16.4.2 | All | All | All |
| Application | Debian | Dpkg | 1.16.4.3 | All | All | All |
| Application | Debian | Dpkg | 1.16.5 | All | All | All |
| Application | Debian | Dpkg | 1.16.6 | All | All | All |
| Application | Debian | Dpkg | 1.16.7 | All | All | All |
| Application | Debian | Dpkg | 1.16.8 | All | All | All |
| Application | Debian | Dpkg | 1.16.9 | All | All | All |
| Application | Debian | Dpkg | 1.17.0 | All | All | All |
| Application | Debian | Dpkg | 1.17.1 | All | All | All |
| Application | Debian | Dpkg | 1.17.2 | All | All | All |
| Application | Debian | Dpkg | 1.17.3 | All | All | All |
| Application | Debian | Dpkg | 1.17.4 | All | All | All |
| Application | Debian | Dpkg | 1.17.5 | All | All | All |
| Application | Debian | Dpkg | 1.17.6 | All | All | All |
| Application | Debian | Dpkg | 1.17.7 | All | All | All |
| Application | Debian | Dpkg | 1.17.8 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| oss-security - CVE request: directory traversal in DSA-2915-1-patched dpkg in Debian squeeze | af854a3a-2127-422b-91ae-364da2661108 | openwall.com | |
| oss-security - Re: CVE request: another path traversal in dpkg-source during unpack | af854a3a-2127-422b-91ae-364da2661108 | openwall.com | |
| #746306 - dpkg: CVE-2014-0471 fix introduces the vulnerability into squeeze - Debian Bug report logs | af854a3a-2127-422b-91ae-364da2661108 | bugs.debian.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.