Bug#774989: kgb: directory traversal vulnerability

2015-01-18 Thread Salvatore Bonaccorso
Control: retitle -1 kgb: CVE-2015-1192: directory traversal vulnerability Hi, CVE-2015-1192 was assigned for this issue. Regards, Salvatore -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#774989: kgb: directory traversal vulnerability

2015-01-09 Thread Alexander Cherepanov
Package: kgb Version: 1.0b4+ds-13.2 Tags: security kgb is susceptible to a directory traversal vulnerability. While extracting an archive, it will happily use absolute paths taken from the archive. This can be exploited by a malicious archive to write files outside the current directory. A s