Package: busybox
Severity: grave
Tags: security
Justification: user security hole


A vulnerability has been found in busybox:

Directory traversal vulnerability in httpd in Rob Landley BusyBox
allows remote attackers to read arbitrary files via URL-encoded
"%2e%2e/" sequences in the URI.

Please mention the CVE id in the changelog.


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Reply via email to