CVE-2015-0840: Medium severity dpkg-dev vulnerability
The dpkg-source command in Debian dpkg before 1.16.16 and 1.17.x before 1.17.25 allows remote attackers to bypass signature verification via a crafted Debian source control file (.dsc).
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2015-0840?
CVE-2015-0840 is classified as a medium severity vulnerability due to its potential to allow remote attackers to bypass signature verification.
How do I fix CVE-2015-0840?
To fix CVE-2015-0840, you should upgrade Debian dpkg to version 1.16.16 or later, or 1.17.x to 1.17.25 or later.
What versions of Debian dpkg are affected by CVE-2015-0840?
CVE-2015-0840 affects Debian dpkg versions prior to 1.16.16 and specific 1.17.x versions before 1.17.25.
What is the nature of the vulnerability in CVE-2015-0840?
CVE-2015-0840 allows attackers to bypass signature verification through a crafted Debian source control file (.dsc).
Is CVE-2015-0840 specific to certain operating systems?
Yes, CVE-2015-0840 primarily affects Debian and Ubuntu Linux distributions using the affected versions of dpkg.