The changelog command in Apt before 1.0.9.2 allows local users to write to arbitrary files via a symlink attack on the changelog file.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-7206
Reference (s):
- BID:70310
- URL: http://www.securityfocus.com/bid/70310
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=763780
- DEBIAN:DSA-3048
- URL: http://www.debian.org/security/2014/dsa-3048