CVE-2011-0725
published 2011-02-23CVE-2011-0725: Absolute path traversal vulnerability in the org.debian.apt.UpdateCachePartially method in worker.py in Aptdaemon 0.40 in Ubuntu 10.10 and 11.04 allows local…
PriorityP418medium4.9CVSS 2.0
AVLACLAuNCCINAN
EPSS
0.39%
31.9th percentile
Absolute path traversal vulnerability in the org.debian.apt.UpdateCachePartially method in worker.py in Aptdaemon 0.40 in Ubuntu 10.10 and 11.04 allows local users to read arbitrary files via a full pathname in the sources_list argument, related to the D-Bus interface.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| sebastian_heinlein | aptdaemon | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3qfx-62r9-w7q6: Absolute path traversal vulnerability in the org
ghsa_unreviewed·2022-05-17
CVE-2011-0725 [MEDIUM] CWE-22 GHSA-3qfx-62r9-w7q6: Absolute path traversal vulnerability in the org
Absolute path traversal vulnerability in the org.debian.apt.UpdateCachePartially method in worker.py in Aptdaemon 0.40 in Ubuntu 10.10 and 11.04 allows local users to read arbitrary files via a full pathname in the sources_list argument, related to the D-Bus interface.
Ubuntu
Aptdaemon vulnerability
vendor_ubuntu·2011-02-22
CVE-2011-0725 Aptdaemon vulnerability
Title: Aptdaemon vulnerability
Sergey Nizovtsev discovered that Aptdaemon incorrectly filtered certain
arguments when using its D-Bus interface. A local attacker could use this
flaw to bypass security restrictions and view sensitive information by
reading arbitrary files.
Instructions: In general, a standard system update will make all the necessary changes.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/46490http://www.securitytracker.com/id?1025107http://www.ubuntu.com/usn/USN-1068-1http://www.vupen.com/english/advisories/2011/0459https://bugs.launchpad.net/bugs/722228https://exchange.xforce.ibmcloud.com/vulnerabilities/65652http://www.securityfocus.com/bid/46490http://www.securitytracker.com/id?1025107http://www.ubuntu.com/usn/USN-1068-1http://www.vupen.com/english/advisories/2011/0459https://bugs.launchpad.net/bugs/722228https://exchange.xforce.ibmcloud.com/vulnerabilities/65652
2011-02-23
Published