ECHO-9fa2-4bcd-f5ba

See a problem?
Import Source
https://advisory.echohq.com/osv/ECHO-9fa2-4bcd-f5ba.json
JSON Data
https://api.osv.dev/v1/vulns/ECHO-9fa2-4bcd-f5ba
Upstream
Withdrawn
2026-01-08T16:00:16Z
Published
2026-05-13T18:23:19Z
Modified
2026-09-15T03:33:35Z
Summary
gccross in dpkg-cross 2.3.0 allows local users to overwrite arbitrary files via a symlink attack on the tmp/gccross2.log temporary file. The vendor disputes this vulnerability, stating that "There is no sense in this bug - the script is installed in /usr/share/ and is called under specific cross-building environments within a chroot".
Details
References

Affected packages

Echo / dpkg-cross

Package

Name
dpkg-cross
Purl
pkg:deb/echo/dpkg-cross

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.6.20

Database specific

source
"https://advisory.echohq.com/osv/ECHO-9fa2-4bcd-f5ba.json"