USN-2820-1: dpkg vulnerability
26 November 2015
dpkg-deb could be made to crash or run programs as your login if it opened a specially crafted file.
Releases
Packages
- dpkg - Debian package management system
Details
Hanno Boeck discovered that the dpkg-deb tool incorrectly handled certain
old style Debian binary packages. If a user or an automated system were
tricked into unpacking a specially crafted binary package, a remote
attacker could possibly use this issue to execute arbitrary code.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 15.10
Ubuntu 15.04
Ubuntu 14.04
Ubuntu 12.04
In general, a standard system update will make all the necessary changes.