exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

Debian Security Advisory 3407-1

Debian Security Advisory 3407-1
Posted Nov 27, 2015
Authored by Debian | Site debian.org

Debian Linux Security Advisory 3407-1 - Hanno Boeck discovered a stack-based buffer overflow in the dpkg-deb component of dpkg, the Debian package management system. This flaw could potentially lead to arbitrary code execution if a user or an automated system were tricked into processing a specially crafted Debian binary package (.deb) in the old style Debian binary package format.

tags | advisory, overflow, arbitrary, code execution
systems | linux, debian
advisories | CVE-2015-0860
SHA-256 | 9598ae2264f8a14638f87a3ca5d821950ee36da44b3324ea62f986b8f2e0c4d0

Debian Security Advisory 3407-1

Change Mirror Download
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian Security Advisory DSA-3407-1 security@debian.org
https://www.debian.org/security/ Salvatore Bonaccorso
November 26, 2015 https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : dpkg
CVE ID : CVE-2015-0860

Hanno Boeck discovered a stack-based buffer overflow in the dpkg-deb
component of dpkg, the Debian package management system. This flaw could
potentially lead to arbitrary code execution if a user or an automated
system were tricked into processing a specially crafted Debian binary
package (.deb) in the old style Debian binary package format.

This update also includes updated translations and additional bug fixes.

For the oldstable distribution (wheezy), this problem has been fixed
in version 1.16.17.

For the stable distribution (jessie), this problem has been fixed in
version 1.17.26.

We recommend that you upgrade your dpkg packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: debian-security-announce@lists.debian.org
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIcBAEBCgAGBQJWV0zYAAoJEAVMuPMTQ89EJWAP/jhh6XHbUb0Bk2B4xmcegVRe
kxvBDVF6SIJfXEYW8nv5p52DiOom+cF+J36p1TbQd0MyehgxfR3uNaE67x4LpMJW
uNbkXnwetaHO6z0/ELfPSOWRKovokmoaoveFJLH7UpOa8GmcxAHo7w79HNd2wvNr
TAQbcNHXyhxc540sos+usYpIuQa+EqLhBpPmA45vmXQK9lgM10Z/cRqckD49P0FF
uldHEXu4yM/n/jsFqRxB0WlXuIJg52DoaGwRMUC0h/kZ6wgg3qQFuNgnrtyDDJaP
liOuXF3zj3Q6b7mxiMVwb3faFZpFlmJc4q8lo5hw8/kkBhNHZSlHTR+qFdLDQU77
KgaymrxKlwEu0iXlIVpFGHnvFeObiY3hghpC4i2mvOoJHcKzIGX4acZ3QZrJ0VTL
zIYEdpYTYv0O27g/29UvvAmnMBEjAVhKiucyHTy6lyuiyyygrgEHapnVKNuOCR8b
bpLleCsYzbRwxHCpeZ0cWaGi5v4sq4LWc/RkPsXLJt4A729xOhTtdJdtd1E3hfsO
b5yPoNRqt5yYV1SyrURW8Urnt3+U9E6WiwJHyLD3sYvCuCoZe57QvNiKxZ4HcolJ
VWbuQ/8ZGSwp64Qiim78rMDnYOldDkgtp26MLKg10fZU+iGPKHi5sV4FJyzF9olS
B5wh9w1rICCIuWcoF8bJ
=IMnl
-----END PGP SIGNATURE-----
Login or Register to add favorites

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    0 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    0 Files
  • 23
    Apr 23rd
    0 Files
  • 24
    Apr 24th
    0 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close