Bug#774978: pigz: directory traversal vulnerability

2015-01-18 Thread Salvatore Bonaccorso
Control: retitle -1 pigz: CVE-2015-1191: directory traversal vulnerability Hi, CVE-2015-1191 was assigned for this issue in pigz. Regards, Salvatore -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.

Bug#774978: pigz: directory traversal vulnerability

2015-01-09 Thread Alexander Cherepanov
Package: pigz Version: 2.3.1-1 Tags: security pigz is susceptible to directory traversal vulnerabilities. While decompressing a file with restoring file name, it (unlike gzip) will happily use absolute and relative paths taken from the input. This can be exploited by a malicious archive to wri