Vulnerabilities
Vulnerable Software
Debian:  >> Dpkg  >> 1.15.10  Security Vulnerabilities
Dpkg::Source::Archive in dpkg, the Debian package management system, before version 1.21.8, 1.20.10, 1.19.8, 1.18.26 is prone to a directory traversal vulnerability. When extracting untrusted source packages in v2 and v3 source package formats that include a debian.tar, the in-place extraction can lead to directory traversal situations on specially crafted orig.tar and debian.tar tarballs.
CVSS Score
9.8
EPSS Score
0.005
Published
2022-05-26
The dpkg-source command in Debian dpkg before 1.16.16 and 1.17.x before 1.17.25 allows remote attackers to bypass signature verification via a crafted Debian source control file (.dsc).
CVSS Score
4.3
EPSS Score
0.007
Published
2015-04-13
Multiple format string vulnerabilities in the parse_error_msg function in parsehelp.c in dpkg before 1.17.22 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in the (1) package or (2) architecture name.
CVSS Score
6.8
EPSS Score
0.025
Published
2015-01-20


Contact Us

Shodan ® - All rights reserved