Back to Database
Status published
Medium
CVE-2011-0402
dpkg-source in dpkg before 1.14.31 and 1.15.x allows user-assisted remote...
Vulnerability Description
dpkg-source in dpkg before 1.14.31 and 1.15.x allows user-assisted remote attackers to modify arbitrary files via a symlink attack on unspecified files in the .pc directory.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2011-0402
Credits & Attribution
No credits recorded in the NVD database.
References
- http://secunia.com/advisories/42831
- http://lists.fedoraproject.org/pipermail/package-announce/2011-January/053311.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/64614
- http://secunia.com/advisories/42826
- http://lists.fedoraproject.org/pipermail/package-announce/2011-January/053306.html
- http://www.ubuntu.com/usn/USN-1038-1
- http://osvdb.org/70367
- http://www.vupen.com/english/advisories/2011/0040
- http://www.securityfocus.com/bid/45703
- http://www.debian.org/security/2011/dsa-2142
- http://secunia.com/advisories/43054
- http://www.vupen.com/english/advisories/2011/0044
- http://www.vupen.com/english/advisories/2011/0196
More from debian
View All →CVE-2022-48174
There is a stack overflow vulnerability in ash.c:6030 in busybox...
Critical
9.8
CVE-2021-38172
perM 0.4.0 has a Buffer Overflow related to strncpy. (Debian...
Critical
9.8
CVE-2021-36086
The CIL compiler in SELinux 3.2 has a use-after-free in...
Low
3.3
CVE-2021-31799
In RDoc 3.11 through 6.x before 6.3.1, as distributed with...
Unknown
0
CVE-2021-28374
The Debian courier-authlib package before 0.71.1-2 for Courier Authentication Library...
High
7.5
Affected Vendor
debian
View all reports →Affected Software
dpkg
Vulnerable Versions:
0, 1.9.19, 1.9.20, 1.9.21, 1.10, 1.10.1, 1.10.2, 1.10.3, 1.10.4, 1.10.5, 1.10.6, 1.10.7, 1.10.8, 1.10.9, 1.10.10, 1.10.11, 1.10.12, 1.10.13, 1.10.14, 1.10.15, 1.10.16, 1.10.17, 1.10.18, 1.10.18.1, 1.10.19, 1.10.20, 1.10.21, 1.10.22, 1.10.23, 1.10.24, 1.10.25, 1.10.26, 1.10.27, 1.10.28, 1.13.0, 1.13.1, 1.13.2, 1.13.3, 1.13.4, 1.13.5, 1.13.6, 1.13.7, 1.13.8, 1.13.9, 1.13.10, 1.13.11, 1.13.11.1, 1.13.12, 1.13.13, 1.13.14, 1.13.15, 1.13.16, 1.13.17, 1.13.18, 1.13.19, 1.13.20, 1.13.21, 1.13.22, 1.13.23, 1.13.24, 1.13.25, 1.14.0, 1.14.1, 1.14.2, 1.14.3, 1.14.4, 1.14.5, 1.14.6, 1.14.7, 1.14.8, 1.14.9, 1.14.10, 1.14.11, 1.14.12, 1.14.13, 1.14.14, 1.14.15, 1.14.16, 1.14.16.1, 1.14.16.2, 1.14.16.3, 1.14.16.4, 1.14.16.5, 1.14.16.6, 1.14.17, 1.14.18, 1.14.19, 1.14.20, 1.14.21, 1.14.22, 1.14.23, 1.14.24, 1.14.25, 1.14.26, 1.14.27, 1.14.28, 1.14.29, 1.15.0, 1.15.1, 1.15.2, 1.15.3, 1.15.3.1, 1.15.4, 1.15.4.1, 1.15.5, 1.15.5.1, 1.15.5.2, 1.15.5.3, 1.15.5.4, 1.15.5.5, 1.15.5.6, 1.15.6, 1.15.6.1, 1.15.7, 1.15.7.1, 1.15.7.2, 1.15.8, 1.15.8.1, 1.15.8.2, 1.15.8.3, 1.15.8.4, 1.15.8.5, 1.15.8.6, 1.15.8.7, 1.15.8.8
Timeline
Official Publish:
January 11th, 2011
Last Modified:
August 6th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.