Packages
- dpkg - Debian package management system
Details
Jann Horn discovered that dpkg incorrectly validated signatures when
extracting local source packages. If a user or an automated system were
tricked into unpacking a specially crafted source package, a remote
attacker could bypass signature verification checks.
Jann Horn discovered that dpkg incorrectly validated signatures when
extracting local source packages. If a user or an automated system were
tricked into unpacking a specially crafted source package, a remote
attacker could bypass signature verification checks.
Update instructions
In general, a standard system update will make all the necessary changes.
Learn more about how to get the fixes.The problem can be corrected by updating your system to the following package versions:
Ubuntu Release | Package Version | ||
---|---|---|---|
14.10 utopic | libdpkg-perl – 1.17.13ubuntu1.1 | ||
14.04 trusty | libdpkg-perl – 1.17.5ubuntu5.4 | ||
12.04 precise | libdpkg-perl – 1.16.1.2ubuntu7.6 | ||
10.04 lucid | dpkg-dev – 1.15.5.6ubuntu4.10 |
Reduce your security exposure
Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.