Bug#774954: ha: directory traversal vulnerabilities

2015-01-18 Thread Salvatore Bonaccorso
Control: retitle -1 ha: CVE-2015-1198: directory traversal vulnerabilities Hi, This has been assigned CVE-2015-1198 by MITRE. Regards, Salvatore -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#774954: Fwd: Re: Bug#774954: ha: directory traversal vulnerabilities

2015-01-09 Thread Mikhail Gusarov
package ha severity 774954 grave tag 774954 +help thanks > ha is susceptible to directory traversal vulnerabilities. While > extracting an archive, it will happily use absolute and relative paths > taken from the archive. This can be exploited by a malicious archive to > write files outside the

Bug#774954: ha: directory traversal vulnerabilities

2015-01-09 Thread Alexander Cherepanov
Package: ha Version: 0.999p+dfsg-5 Tags: security ha is susceptible to directory traversal vulnerabilities. While extracting an archive, it will happily use absolute and relative paths taken from the archive. This can be exploited by a malicious archive to write files outside the current direc