CVE-2014-8625: Medium severity dpkg-dev vulnerability
Multiple format string vulnerabilities in the parseerrormsg function in parsehelp.c in dpkg before 1.17.22 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in the (1) package or (2) architecture name.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-8625?
CVE-2014-8625 has a moderate severity rating as it allows remote attackers to cause denial of service and potentially execute arbitrary code.
How do I fix CVE-2014-8625?
To fix CVE-2014-8625, upgrade to a patched version of dpkg, specifically version 1.20.10 or later.
Which versions of dpkg are affected by CVE-2014-8625?
CVE-2014-8625 affects dpkg versions prior to 1.17.22.
Can CVE-2014-8625 be exploited remotely?
Yes, CVE-2014-8625 can be exploited by remote attackers via crafted format string specifiers.
What are the potential impacts of exploiting CVE-2014-8625?
Exploiting CVE-2014-8625 can lead to crashes of the dpkg service and may allow execution of arbitrary code.