UbuntuUpdates.org

Package "dpkg"

Name: dpkg

Description:

Debian package management system

Latest version: 1.17.5ubuntu5.8
Release: trusty (14.04)
Level: updates
Repository: main
Homepage: https://wiki.debian.org/Teams/Dpkg

Links


Download "dpkg"


Other versions of "dpkg" in Trusty

Repository Area Version
base main 1.17.5ubuntu5
security main 1.17.5ubuntu5.6

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 1.17.5ubuntu5.3 2014-06-10 13:07:06 UTC

  dpkg (1.17.5ubuntu5.3) trusty-security; urgency=medium

  * SECURITY UPDATE: arbitrary file modification via dpkg-source
    - scripts/Dpkg/Source/Patch.pm: Use a better regex for patch header
      parsing
    - 5348cbc981a65c3c9b05bb4d13553bda930c2d78
    - CVE-2014-3864
    - CVE-2014-3865
 -- Marc Deslauriers <email address hidden> Mon, 09 Jun 2014 12:34:57 -0400

Source diff to previous version
CVE-2014-3864 Directory traversal vulnerability in dpkg-source in dpkg-dev 1.3.0 ...
CVE-2014-3865 Multiple directory traversal vulnerabilities in dpkg-source in ...

Version: 1.17.5ubuntu5.2 2014-05-01 16:07:37 UTC

  dpkg (1.17.5ubuntu5.2) trusty-security; urgency=medium

  * SECURITY UPDATE: directory traversal in dpkg-source
    - scripts/Dpkg/Source/Patch.pm: outright reject C-style filenames in
      patches
    - a12eb58959d0a10584a428f4a3103a49204c410f
    - CVE-2014-0471
 -- Marc Deslauriers <email address hidden> Thu, 01 May 2014 07:59:19 -0400

Source diff to previous version
CVE-2014-0471 dpkg-source: directory traversal during unpack

Version: 1.17.5ubuntu5.1 2014-04-28 14:07:53 UTC

  dpkg (1.17.5ubuntu5.1) trusty-security; urgency=medium

  * SECURITY UPDATE: directory traversal in dpkg-source
    - scripts/Dpkg/Source/Patch.pm: correctly parse C-style diff
      filenames.
    - Patch thanks to Guillem Jover <email address hidden>
    - CVE-2014-0471
 -- Marc Deslauriers <email address hidden> Wed, 23 Apr 2014 19:46:35 -0400

CVE-2014-0471 dpkg-source: directory traversal during unpack



About   -   Send Feedback to @ubuntu_updates