VDB
GCVE-110-MAGEIA-2014-289
GCVE-110-MAGEIA-2014-289
Advisory Published
Jakub Wilk discovered that dpkg did not correctly parse C-style filename
quoting, allowing for paths to be traversed when unpacking a source package,
leading to the creation of files outside the directory of the source being
unpacked (CVE-2014-0471).
Multiple vulnerabilities were discovered in dpkg that allow file modification
through path traversal when unpacking source packages with especially-crafted
patch files (CVE-2014-3864, CVE-2014-3865).
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Mageia | dpkg | 1.16.15-1.1.mga3 (unaffected), 0 (affected) | — |
| Mageia | dpkg | 0 (affected), 1.17.10-1.1.mga4 (unaffected) | — |
Browse GCVE Records
74,267 records in the GCVE database · Updated July 22, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.