Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2014-8625

Опубликовано: 20 янв. 2015
Источник: debian
EPSS Низкий

Описание

Multiple format string vulnerabilities in the parse_error_msg function in parsehelp.c in dpkg before 1.17.22 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in the (1) package or (2) architecture name.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
dpkgfixed1.17.22package
dpkgfixed1.16.16wheezypackage
dpkgnot-affectedsqueezepackage

Примечания

  • Rendered non-exploitable by toolchain hardening

  • https://bugs.launchpad.net/ubuntu/+source/dpkg/+bug/1389135

  • Regression introduced with https://anonscm.debian.org/cgit/dpkg/dpkg.git/commit/?id=0b8652b226a7601dfd71471797d15168a7337242 (1.16.2)

EPSS

Процентиль: 87%
0.03296
Низкий

Связанные уязвимости

ubuntu
больше 11 лет назад

Multiple format string vulnerabilities in the parse_error_msg function in parsehelp.c in dpkg before 1.17.22 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in the (1) package or (2) architecture name.

nvd
больше 11 лет назад

Multiple format string vulnerabilities in the parse_error_msg function in parsehelp.c in dpkg before 1.17.22 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in the (1) package or (2) architecture name.

github
больше 4 лет назад

Multiple format string vulnerabilities in the parse_error_msg function in parsehelp.c in dpkg before 1.17.22 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in the (1) package or (2) architecture name.

EPSS

Процентиль: 87%
0.03296
Низкий