dpkg 1.14.29 source package in Debian

Changelog

dpkg (1.14.29) stable-security; urgency=high


  * Modify dpkg-source to error out when it would apply patches containing
    insecure paths (with "/../") and also error out when it would apply a
    patch through a symlink. Those checks are required as patch will happily
    modify files outside of the target directory and unpacking a source package
    should not be able to have any side-effect outside of the target
    directory. Fixes CVE-2010-0396.
  * Also error out when the quilt series contains a path with "/../" as this
    can cause patch to create files outside of the source package due
    to the -B .pc/$path option that it gets.

 -- Raphael Hertzog <email address hidden>  Fri, 05 Mar 2010 22:25:05 +0100

Upload details

Uploaded by:
Dpkg Mailing List
Uploaded to:
Lenny
Original maintainer:
Dpkg Mailing List
Architectures:
any
Section:
admin
Urgency:
Very Urgent

See full publishing history Publishing

Series Pocket Published Component Section

Builds

Downloads

File Size SHA-256 Checksum
dpkg_1.14.29.dsc 1.5 KiB b2c1b31bead8baeae149ebc7a88ec7c410e34e46bb9b06fc68625d991c38a2be
dpkg_1.14.29.tar.gz 6.5 MiB ea7ec1c861af43ba534a0d7997774a5f1fd4e25a7eea4ff229c9c7bf89aed633

No changes file available.

Binary packages built by this source