Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2015-0860

Опубликовано: 03 дек. 2015
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 7.5

Описание

Off-by-one error in the extracthalf function in dpkg-deb/extract.c in the dpkg-deb component in Debian dpkg 1.16.x before 1.16.17 and 1.17.x before 1.17.26 allows remote attackers to execute arbitrary code via the archive magic version number in an "old-style" Debian binary package, which triggers a stack-based buffer overflow.

РелизСтатусПримечание
devel

released

1.18.4ubuntu1
esm-infra-legacy/trusty

released

1.17.5ubuntu5.5
precise

released

1.16.1.2ubuntu7.7
trusty

released

1.17.5ubuntu5.5
trusty/esm

released

1.17.5ubuntu5.5
upstream

needs-triage

vivid

released

1.17.25ubuntu1.1
vivid/stable-phone-overlay

ignored

vivid/ubuntu-core

released

1.17.25ubuntu1.1
wily

released

1.18.2ubuntu5.1

Показывать по

EPSS

Процентиль: 89%
0.04909
Низкий

7.5 High

CVSS2

Связанные уязвимости

nvd
около 10 лет назад

Off-by-one error in the extracthalf function in dpkg-deb/extract.c in the dpkg-deb component in Debian dpkg 1.16.x before 1.16.17 and 1.17.x before 1.17.26 allows remote attackers to execute arbitrary code via the archive magic version number in an "old-style" Debian binary package, which triggers a stack-based buffer overflow.

debian
около 10 лет назад

Off-by-one error in the extracthalf function in dpkg-deb/extract.c in ...

suse-cvrf
больше 8 лет назад

Security update for dpkg

suse-cvrf
почти 9 лет назад

Security update for dpkg

github
больше 3 лет назад

Off-by-one error in the extracthalf function in dpkg-deb/extract.c in the dpkg-deb component in Debian dpkg 1.16.x before 1.16.17 and 1.17.x before 1.17.26 allows remote attackers to execute arbitrary code via the archive magic version number in an "old-style" Debian binary package, which triggers a stack-based buffer overflow.

EPSS

Процентиль: 89%
0.04909
Низкий

7.5 High

CVSS2