CVE-2015-0860
Publication date 26 November 2015
Last updated 24 July 2024
Ubuntu priority
Off-by-one error in the extracthalf function in dpkg-deb/extract.c in the dpkg-deb component in Debian dpkg 1.16.x before 1.16.17 and 1.17.x before 1.17.26 allows remote attackers to execute arbitrary code via the archive magic version number in an "old-style" Debian binary package, which triggers a stack-based buffer overflow.
Status
Package | Ubuntu Release | Status |
---|---|---|
dpkg | ||
14.04 LTS trusty |
Fixed 1.17.5ubuntu5.5
|
|
References
Related Ubuntu Security Notices (USN)
- USN-2820-1
- dpkg vulnerability
- 26 November 2015