Off-by-one error in the extracthalf function in dpkg-deb/extract.c in the dpkg-deb component in Debian dpkg 1.16.x before 1.16.17 and 1.17.x before 1.17.26 allows remote attackers to execute arbitrary code via the archive magic version number in an "old-style" Debian binary package, which triggers a stack-based buffer overflow.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade dpkg | Dec 3, 2015 | Nov 26, 2015 |
| Freebsd | — | Upgrade dpkg | Dec 10, 2025 | Dec 25, 2015 |
| Gentoo Linux | — | Upgrade app-arch/dpkg. | Oct 30, 2017 | Dec 3, 2015 |
| Suse | — | Upgrade sles12sp1-docker-imageUpgrade update-alternatives | Apr 24, 2017 | Dec 3, 2015 |
| Ubuntu | — | Upgrade dpkg | Dec 3, 2015 | Nov 26, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub