Vulnerability Bulletins

DSA-3289 p7zip - security update

   
Affected software Debian
 
Alexander Cherepanov discovered that p7zip is susceptible to adirectory traversal vulnerability. While extracting an archive, itwill extract symlinks and then follow them if they are referenced infurther entries. This can be exploited by a rogue archive to writefiles outside the current directory.

More info:

https://www.debian.org/security/2015/dsa-3289