Debian dpkg-source command signature verification Bypass Vulnerability (CVE-2015-0840)
Debian dpkg-source command signature verification Bypass Vulnerability (CVE-2015-0840)
Release date:
Updated on:
Affected Systems:
Debian dpkg <1.17.25
Debian dpkg <1.16.16
Description:
CVE (CAN) ID: CVE-2015-0840
Dpkg is a suite management system specially developed for "Debian" to facilitate software installation, update, and removal.
In versions earlier than Debian dpkg 1.16.16 and earlier than 1.17.25, The dpkg-source command has a security vulnerability. Remote attackers can bypass signature verification by constructing a. dsc file.
<* Source: Jann Horn
*>
Suggestion:
Vendor patch:
Debian
------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Https://packages.debian.org/search? Keywords = dpkg
Http://www.debian.org/security/2015/dsa-3217
Http://www.ubuntu.com/usn/USN-2566-1
This article permanently updates the link address: