CVE-2007-0159
Publication date 10 January 2007
Last updated 24 July 2024
Ubuntu priority
Directory traversal vulnerability in the GeoIP_update_database_general function in libGeoIP/GeoIPUpdate.c in GeoIP 1.4.0 allows remote malicious update servers (possibly only update.maxmind.com) to overwrite arbitrary files via a .. (dot dot) in the database filename, which is returned by a request to app/update_getfilename.
Status
Package | Ubuntu Release | Status |
---|---|---|
geoip | 7.04 feisty |
Fixed 1.3.17-1.1
|
6.10 edgy |
Fixed 1.3.17-1ubuntu0.1
|
|
6.06 LTS dapper |
Fixed 1.3.14-2ubuntu0.1
|