Debian Security Advisory

DLA-1445-3 busybox -- LTS security update

Date Reported:
03 Aug 2018
Affected Packages:
Security database references:
No other external database security references currently available.
More information:

It was found that the security update of busybox announced as DLA-1445-1 to prevent the exploitation of CVE-2011-5325, a symlinking attack, was too strict in case of cpio archives. This update restores the old behavior.

For Debian 8 Jessie, this problem has been fixed in version 1:1.22.0-9+deb8u4.

We recommend that you upgrade your busybox packages.

Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: