peter bassill · operator
$ cve CVE-2014-3865 JSON

CVE-2014-3865 EXPLOIT

6.4
MEDIUM · CVSS 2.0 · EPSS 7.3% (pctl 94)

Patch early

A public exploit exists.

Description

Multiple directory traversal vulnerabilities in dpkg-source in dpkg-dev 1.3.0 allow remote attackers to modify files outside of the intended directories via a source package with a crafted Index: pseudo-header in conjunction with (1) missing --- and +++ header lines or (2) a +++ header line with a blank pathname.

Scoring

CVSS6.4 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:N/C:N/I:P/A:P
EPSS7.32% — more likely to be exploited than 94% of all CVEs
WeaknessCWE-22
On CISA KEVno
Public exploityes
Published2014-05-30
Last modified2026-06-17

Affected (1)

VendorProduct
debiandpkg-dev

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD