Vulnerability Bulletins

DSA-2915 dpkg - security update

   
Affected software Debian
 
Jakub Wilk discovered that dpkg did not correctly parse C-stylefilename quoting, allowing for paths to be traversed when unpacking asource package - leading to the creation of files outside the directoryof the source being unpacked.

More info:

http://www.debian.org/security/2014/dsa-2915