Debian Security Advisory

DLA-245-1 p7zip -- LTS security update

Date Reported:
14 Jun 2015
Affected Packages:
p7zip
Vulnerable:
Yes
Security database references:
In the Debian bugtracking system: Bug 774660.
In Mitre's CVE dictionary: CVE-2015-1038.
More information:

Alexander Cherepanov discovered that p7zip is susceptible to a directory traversal vulnerability. While extracting an archive, it will extract symlinks and then follow them if they are referenced in further entries. This can be exploited by a rogue archive to write files outside the current directory.

For the oldoldstable distribution (squeeze), this problem has been fixed in version 9.04~dfsg.1-1+deb6u1.

For the oldstable distribution (wheezy) and stable distribution (jessie), this problem will be fixed soon.