File _patchinfo of Package patchinfo.4525
<patchinfo incident="4525"> <issue id="957160" tracker="bnc">VUL-1: CVE-2015-0860: dpkg: stack overflows and out of bounds read</issue> <issue id="2015-0860" tracker="cve" /> <category>security</category> <rating>moderate</rating> <packager>pgajdos</packager> <description> This update for dpkg fixes the following issues: This security issue was fixed: - CVE-2015-0860: Off-by-one error in the extracthalf function in dpkg-deb/extract.c in the dpkg-deb component in dpkg allowed remote attackers to execute arbitrary code via the archive magic version number in an "old-style" Debian binary package, which triggered a stack-based buffer overflow (bsc#957160). </description> <summary>Security update for dpkg</summary> </patchinfo>