CVE-2014-0471
Directory traversal vulnerability in the unpacking functionality in dpkg before 1.15.9, 1.16.x before 1.16.13, and 1.17.x before 1.17.8 allows remote attackers to write arbitrary files via a crafted source package, related to "C-style filename quoting."
View on NVDSeverity
N/A
EPSS
Probability of exploitation (next 30 days): 0.0024 (0.2%)
Percentile: 47.7%
EPSS: 2026-05-06
Affects
debian:dpkgcanonical:ubuntu_linuxTechnical description
Directory traversal vulnerability in the unpacking functionality in dpkg before 1.15.9, 1.16.x before 1.16.13, and 1.17.x before 1.17.8 allows remote attackers to write arbitrary files via a crafted source package, related to "C-style filename quoting."
Published: 4/30/2014, 2:22:06 PM
Last modified: 5/6/2026, 10:30:45 PM