Off-by-one error in the extracthalf function in dpkg-deb/extract.c in the dpkg-deb component in Debian dpkg 1.16.x before 1.16.17 and 1.17.x before 1.17.26 allows remote attackers to execute arbitrary code via the archive magic version number in an old-style Debian binary package, which triggers a stack-based buffer overflow.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Ubuntu_linux | Canonical | 12.04 (including) | 12.04 (including) |
Ubuntu_linux | Canonical | 14.04 (including) | 14.04 (including) |
Ubuntu_linux | Canonical | 15.04 (including) | 15.04 (including) |
Ubuntu_linux | Canonical | 15.10 (including) | 15.10 (including) |
Dpkg | Ubuntu | devel | * |
Dpkg | Ubuntu | precise | * |
Dpkg | Ubuntu | trusty | * |
Dpkg | Ubuntu | vivid | * |
Dpkg | Ubuntu | vivid/stable-phone-overlay | * |
Dpkg | Ubuntu | vivid/ubuntu-core | * |
Dpkg | Ubuntu | wily | * |