← Back

CVE-2015-0860

nvd nist
Published: Dec 3, 2015Modified: May 6, 2026

JSON object

Loading...
7.5
Vector
AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploitability: 10.0 / Impact: 6.4
Source: NVD

Description

Off-by-one error in the extracthalf function in dpkg-deb/extract.c in the dpkg-deb component in Debian dpkg 1.16.x before 1.16.17 and 1.17.x before 1.17.26 allows remote attackers to execute arbitrary code via the archive magic version number in an "old-style" Debian binary package, which triggers a stack-based buffer overflow.

Affected (52)

1 product
Ubuntu Linux
1 product
Dpkg
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Canonical
Version 12.04
Version 14.04
Version 15.04
Version 15.10
Configuration B
48 vulnerable
Vulnerable SoftwareAffected Versions
Debian
Version 1.16.0.1
Version 1.16.0.2
Version 1.16.0.3
Version 1.16.0
Version 1.16.1.1
Version 1.16.1.2
Version 1.16.10
Version 1.16.11
Version 1.16.12
Version 1.16.15
Version 1.16.1
Version 1.16.2
Version 1.16.3
Version 1.16.4.1
Version 1.16.4.2
Version 1.16.4.3
Version 1.16.4
Version 1.16.5
Version 1.16.6
Version 1.16.7
Version 1.16.8
Version 1.16.9
Version 1.17.0
Version 1.17.10
Version 1.17.11
Version 1.17.12
Version 1.17.13
Version 1.17.14
Version 1.17.15
Version 1.17.16
Version 1.17.17
Version 1.17.18
Version 1.17.19
Version 1.17.1
Version 1.17.20
Version 1.17.21
Version 1.17.22
Version 1.17.23
Version 1.17.24
Version 1.17.25
Version 1.17.2
Version 1.17.3
Version 1.17.4
Version 1.17.5
Version 1.17.6
Version 1.17.7
Version 1.17.8
Version 1.17.9

Related CWEs

Timeline

No history available yet.