Debian Security Advisory
DSA-3289-1 p7zip -- security update
- Date Reported:
- 15 Jun 2015
- Affected Packages:
- p7zip
- Vulnerable:
- Yes
- Security database references:
- In the Debian bugtracking system: Bug 774660.
In Mitre's CVE dictionary: CVE-2015-1038. - More information:
-
Alexander Cherepanov discovered that p7zip is susceptible to a directory traversal vulnerability. While extracting an archive, it will extract symlinks and then follow them if they are referenced in further entries. This can be exploited by a rogue archive to write files outside the current directory.
For the oldstable distribution (wheezy), this problem has been fixed in version 9.20.1~dfsg.1-4+deb7u1.
For the stable distribution (jessie), this problem has been fixed in version 9.20.1~dfsg.1-4.1+deb8u1.
For the unstable distribution (sid), this problem has been fixed in version 9.20.1~dfsg.1-4.2.
We recommend that you upgrade your p7zip packages.