Vulnerability Solutions

The WatchMouse Periodic Vulnerability Scan checks for the vulnerability below. To see the most recently added vulnerability solutions that are scanned by WatchMouse, go to the Vulnerability Solutions overview

Category: Debian Local Security Checks Risk factor: High Added: 11 Mar 2010
Synopsis:

The remote host is missing the DSA-2011 security update

Description:

William Grant discovered that the dpkg-source component of dpkg, the low-level infrastructure for handling the installation and removal of Debian software packages, is vulnerable to path traversal attacks. A specially crafted Debian source package can lead to file modification outside of the destination directory when extracting the package content. For the stable distribution (lenny), this problem has been fixed in version 1.14.29.

See also:

http://www.debian.org/security/2010/dsa-2011

Solution:

The Debian project recommends that you upgrade your dpkg packages.

Risk factor:

High