Vulnerabilities (CVE)

Filtered by vendor Debian Subscribe
Filtered by product Dpkg-cross
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2008-4950 1 Debian 1 Dpkg-cross 2024-04-11 6.9 MEDIUM N/A
gccross in dpkg-cross 2.3.0 allows local users to overwrite arbitrary files via a symlink attack on the tmp/gccross2.log temporary file. NOTE: the vendor disputes this vulnerability, stating that "There is no sense in this bug - the script ... is called under specific cross-building environments within a chroot.