Описание
It was discovered that dpkg-deb (a component of dpkg, the Debian package management system) does not properly validate the end of the data stream when uncompressing a zstd-compressed .deb archive, which may result in denial of service (infinite loop spinning the CPU).
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | 1.23.7ubuntu1 |
| esm-infra-legacy/trusty | not-affected | |
| esm-infra-legacy/xenial | not-affected | |
| esm-infra/bionic | not-affected | |
| esm-infra/focal | not-affected | |
| esm-infra/xenial | not-affected | |
| jammy | not-affected | 1.21.1ubuntu2.6 |
| noble | released | 1.22.6ubuntu6.6 |
| questing | released | 1.22.21ubuntu3.2 |
| resolute | not-affected | 1.23.7ubuntu1 |
Показывать по
EPSS
7.5 High
CVSS3
Связанные уязвимости
It was discovered that dpkg-deb (a component of dpkg, the Debian package management system) does not properly validate the end of the data stream when uncompressing a zstd-compressed .deb archive, which may result in denial of service (infinite loop spinning the CPU).
It was discovered that dpkg-deb (a component of dpkg, the Debian packa ...
It was discovered that dpkg-deb (a component of dpkg, the Debian package management system) does not properly validate the end of the data stream when uncompressing a zstd-compressed .deb archive, which may result in denial of service (infinite loop spinning the CPU).
EPSS
7.5 High
CVSS3