Candidate: CVE-2013-4510 PublicDate: 2013-11-18 02:55:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4510 https://bugs.tryton.org/issue3446 Description: Directory traversal vulnerability in the client in Tryton 3.0.0, as distributed before 20131104 and earlier, allows remote servers to write arbitrary files via path separators in the extension of a report. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: Patches_tryton-client: upstream_tryton-client: released (2.8.4-1) lucid_tryton-client: ignored (reached end-of-life) precise_tryton-client: ignored (reached end-of-life) precise/esm_tryton-client: DNE (precise was needs-triage) quantal_tryton-client: ignored (reached end-of-life) raring_tryton-client: ignored (reached end-of-life) saucy_tryton-client: ignored (reached end-of-life) trusty_tryton-client: not-affected (2.8.4-1) trusty/esm_tryton-client: DNE (trusty was not-affected [2.8.4-1]) utopic_tryton-client: not-affected (2.8.4-1) vivid_tryton-client: not-affected (2.8.4-1) vivid/stable-phone-overlay_tryton-client: DNE vivid/ubuntu-core_tryton-client: DNE wily_tryton-client: not-affected (2.8.4-1) xenial_tryton-client: not-affected (2.8.4-1) yakkety_tryton-client: not-affected (2.8.4-1) zesty_tryton-client: not-affected (2.8.4-1) devel_tryton-client: not-affected (2.8.4-1)