Debian Security Advisory
DLA-245-1 p7zip -- LTS security update
- Date Reported:
- 14 Jun 2015
- Affected Packages:
- p7zip
- Vulnerable:
- Yes
- Security database references:
- In the Debian bugtracking system: Bug 774660.
In Mitre's CVE dictionary: CVE-2015-1038. - More information:
-
Alexander Cherepanov discovered that p7zip is susceptible to a directory traversal vulnerability. While extracting an archive, it will extract symlinks and then follow them if they are referenced in further entries. This can be exploited by a rogue archive to write files outside the current directory.
For the oldoldstable distribution (squeeze), this problem has been fixed in version 9.04~dfsg.1-1+deb6u1.
For the oldstable distribution (wheezy) and stable distribution (jessie), this problem will be fixed soon.