Debian Security Advisory

DSA-3289-1 p7zip -- security update

Date Reported:
15 Jun 2015
Affected Packages:
p7zip
Vulnerable:
Yes
Security database references:
In the Debian bugtracking system: Bug 774660.
In Mitre's CVE dictionary: CVE-2015-1038.
More information:

Alexander Cherepanov discovered that p7zip is susceptible to a directory traversal vulnerability. While extracting an archive, it will extract symlinks and then follow them if they are referenced in further entries. This can be exploited by a rogue archive to write files outside the current directory.

For the oldstable distribution (wheezy), this problem has been fixed in version 9.20.1~dfsg.1-4+deb7u1.

For the stable distribution (jessie), this problem has been fixed in version 9.20.1~dfsg.1-4.1+deb8u1.

For the unstable distribution (sid), this problem has been fixed in version 9.20.1~dfsg.1-4.2.

We recommend that you upgrade your p7zip packages.