The dpkg-source command in Debian dpkg before 1.16.16 and 1.17.x before 1.17.25 allows remote attackers to bypass signature verification via a crafted Debian source control file (.dsc).
| Software | From | Fixed in |
|---|---|---|
| debian / dpkg | 1.17.14 | 1.17.14.x |
| debian / dpkg | 1.17.24 | 1.17.24.x |
| debian / dpkg | 1.17.3 | 1.17.3.x |
| debian / dpkg | 1.17.11 | 1.17.11.x |
| debian / dpkg | 1.17.6 | 1.17.6.x |
| debian / dpkg | 1.17.7 | 1.17.7.x |
| debian / dpkg | 1.17.22 | 1.17.22.x |
| debian / dpkg | 1.17.18 | 1.17.18.x |
| debian / dpkg | 1.17.1 | 1.17.1.x |
| debian / dpkg | 1.17.19 | 1.17.19.x |
| debian / dpkg | 1.17.23 | 1.17.23.x |
| debian / dpkg | 1.17.8 | 1.17.8.x |
| debian / dpkg | 1.17.13 | 1.17.13.x |
| debian / dpkg | 1.17.4 | 1.17.4.x |
| debian / dpkg | 1.17.21 | 1.17.21.x |
| debian / dpkg | 1.17.17 | 1.17.17.x |
| debian / dpkg | 1.17.9 | 1.17.9.x |
| debian / dpkg | 1.17.15 | 1.17.15.x |
| debian / dpkg | 1.17.20 | 1.17.20.x |
| debian / dpkg | 1.17.10 | 1.17.10.x |
| debian / dpkg | 1.17.12 | 1.17.12.x |
| debian / dpkg | 1.17.16 | 1.17.16.x |
| debian / dpkg | 1.17.0 | 1.17.0.x |
| debian / dpkg | 1.17.5 | 1.17.5.x |
| debian / dpkg | - | 1.16.15.x |
| debian / dpkg | 1.17.2 | 1.17.2.x |
| canonical / ubuntu_linux | 12.04 | 12.04.x |
| canonical / ubuntu_linux | 14.10 | 14.10.x |
| canonical / ubuntu_linux | 14.04 | 14.04.x |
| canonical / ubuntu_linux | 10.04 | 10.04.x |