diff options
author | Guillem Jover <guillem@debian.org> | 2014-04-15 08:15:44 +0200 |
---|---|---|
committer | Guillem Jover <guillem@debian.org> | 2014-04-28 15:19:40 +0200 |
commit | a82651188476841d190c58693f95827d61959b51 (patch) | |
tree | 1ed9d63297e5ef8cfa587cf633a21546612930d3 /po/ast.po | |
parent | d4dfad8cff69c245516abc570d0bba1f614c1443 (diff) | |
download | dpkg-a82651188476841d190c58693f95827d61959b51.tar.gz |
Dpkg::Source::Patch: Correctly parse C-style diff filenames
We need to strip the surrounding quotes, and unescape any escape
sequence, so that we check the same files that the patch program will
be using, otherwise a malicious package could overpass those checks,
and perform directory traversal attacks on source package unpacking.
Fixes: CVE-2014-0471
Reported-by: Jakub Wilk <jwilk@debian.org>
Diffstat (limited to 'po/ast.po')
0 files changed, 0 insertions, 0 deletions