Vulnerability Bulletins

DSA-4083 poco - security update

   
Affected software Debian
 
Stephan Zeisberg discovered that poco, a collection of open source C++class libraries, did not correctly validate file paths in ZIParchives. An attacker could leverage this flaw to create or overwritearbitrary files.

More info:

https://www.debian.org/security/2018/dsa-4083