Skip to main content

Vendor/product archive

debian / dpkg CVEs

Beta · best-effort

14 CVEs tagged to debian / dpkg2 Critical, 5 High, 7 Medium, 0 Low, 0 Unrated.

CVE-2026-2219

Published Mar 7, 2026

It was discovered that dpkg-deb (a component of dpkg, the Debian package management system) does not properly validate the end of the data stream when uncompressing a zstd-compres…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-6297

Published Jul 1, 2025

It was discovered that dpkg-deb does not properly sanitize directory permissions when extracting a control member into a temporary directory, which is documented as being a safe o…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2017-8283

Published Apr 26, 2017

dpkg-source in dpkg 1.3.0 through 1.18.23 is able to use a non-GNU patch program and does not offer a protection mechanism for blank-indented diff hunks, which allows remote attac…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2015-0860

Published Dec 3, 2015

Off-by-one error in the extracthalf function in dpkg-deb/extract.c in the dpkg-deb component in Debian dpkg 1.16.x before 1.16.17 and 1.17.x before 1.17.26 allows remote attackers…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-0840

Published Apr 13, 2015

The dpkg-source command in Debian dpkg before 1.16.16 and 1.17.x before 1.17.25 allows remote attackers to bypass signature verification via a crafted Debian source control file (…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-8625

Published Jan 20, 2015

Multiple format string vulnerabilities in the parse_error_msg function in parsehelp.c in dpkg before 1.17.22 allow remote attackers to cause a denial of service (crash) and possib…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-3227

Published May 30, 2014

dpkg 1.15.9, 1.16.x before 1.16.14, and 1.17.x before 1.17.9 expect the patch program to be compliant with a need for the "C-style encoded filenames" feature, but is supported in…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-3127

Published May 14, 2014

dpkg 1.15.9 on Debian squeeze introduces support for the "C-style encoded filenames" feature without recognizing that the squeeze patch program lacks this feature, which triggers…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2014-0471

Published Apr 30, 2014

Directory traversal vulnerability in the unpacking functionality in dpkg before 1.15.9, 1.16.x before 1.16.13, and 1.17.x before 1.17.8 allows remote attackers to write arbitrary…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-0402

Published Jan 11, 2011

dpkg-source in dpkg before 1.14.31 and 1.15.x allows user-assisted remote attackers to modify arbitrary files via a symlink attack on unspecified files in the .pc directory.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-1679

Published Jan 11, 2011

Directory traversal vulnerability in dpkg-source in dpkg before 1.14.31 and 1.15.x allows user-assisted remote attackers to modify arbitrary files via directory traversal sequence…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-2768

Published Jun 8, 2010

dpkg 1.9.21 does not properly reset the metadata of a file during replacement of the file in a package upgrade, which might allow local users to gain privileges by creating a hard…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2010-0396

Published Mar 15, 2010

Directory traversal vulnerability in the dpkg-source component in dpkg before 1.14.29 allows remote attackers to modify arbitrary files via a crafted Debian source archive.

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-14 of 14 CVEsPage 1 of 1