Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2014-8625

Опубликовано: 20 янв. 2015
Источник: debian

Описание

Multiple format string vulnerabilities in the parse_error_msg function in parsehelp.c in dpkg before 1.17.22 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in the (1) package or (2) architecture name.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
dpkgfixed1.17.22package
dpkgfixed1.16.16wheezypackage
dpkgnot-affectedsqueezepackage

Примечания

  • Rendered non-exploitable by toolchain hardening

  • https://bugs.launchpad.net/ubuntu/+source/dpkg/+bug/1389135

  • Regression introduced with https://anonscm.debian.org/cgit/dpkg/dpkg.git/commit/?id=0b8652b226a7601dfd71471797d15168a7337242 (1.16.2)

Связанные уязвимости

ubuntu
около 11 лет назад

Multiple format string vulnerabilities in the parse_error_msg function in parsehelp.c in dpkg before 1.17.22 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in the (1) package or (2) architecture name.

nvd
около 11 лет назад

Multiple format string vulnerabilities in the parse_error_msg function in parsehelp.c in dpkg before 1.17.22 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in the (1) package or (2) architecture name.

github
больше 3 лет назад

Multiple format string vulnerabilities in the parse_error_msg function in parsehelp.c in dpkg before 1.17.22 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in the (1) package or (2) architecture name.