Skip to content
Commit a8265118 authored by Guillem Jover's avatar Guillem Jover
Browse files

Dpkg::Source::Patch: Correctly parse C-style diff filenames

We need to strip the surrounding quotes, and unescape any escape
sequence, so that we check the same files that the patch program will
be using, otherwise a malicious package could overpass those checks,
and perform directory traversal attacks on source package unpacking.

Fixes: CVE-2014

-0471

Reported-by: default avatarJakub Wilk <jwilk@debian.org>
parent d4dfad8c
0% or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment