[Bug 1169636] [NEW] lintian: CVE-2013-1429 - path traversal/information disclosure

Niels Thykier niels at thykier.net
Tue Apr 16 16:35:16 UTC 2013


*** This bug is a security vulnerability ***

Public security bug reported:

An "unimportant" security vulnerabilities have been found in Lintian.

In short, using crafted packages an attacker could have Lintian leak
information about the "host" system provided the raw log is available.

Fixes available in 2.5.10.5 and 2.5.12.

(Reference: http://bugs.debian.org/705553)

** Affects: lintian (Ubuntu)
     Importance: Undecided
         Status: New

** Information type changed from Private Security to Public Security

-- 
You received this bug notification because you are a member of Ubuntu
Foundations Bugs, which is subscribed to lintian in Ubuntu.
https://bugs.launchpad.net/bugs/1169636

Title:
  lintian: CVE-2013-1429 - path traversal/information disclosure

Status in “lintian” package in Ubuntu:
  New

Bug description:
  An "unimportant" security vulnerabilities have been found in Lintian.

  In short, using crafted packages an attacker could have Lintian leak
  information about the "host" system provided the raw log is available.

  Fixes available in 2.5.10.5 and 2.5.12.

  (Reference: http://bugs.debian.org/705553)

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/lintian/+bug/1169636/+subscriptions




More information about the foundations-bugs mailing list