6.8
CVSSv2

CVE-2014-8625

Published: 20/01/2015 Updated: 08/09/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 606
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple format string vulnerabilities in the parse_error_msg function in parsehelp.c in dpkg prior to 1.17.22 allow remote malicious users to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in the (1) package or (2) architecture name.

Vulnerable Product Search on Vulmon Subscribe to Product

debian dpkg

Vendor Advisories

Debian Bug report logs - #768485 dpkg: CVE-2014-8625: format string vulnerability Package: dpkg; Maintainer for dpkg is Dpkg Developers <debian-dpkg@listsdebianorg>; Source for dpkg is src:dpkg (PTS, buildd, popcon) Reported by: Jakub Wilk <jwilk@debianorg> Date: Fri, 7 Nov 2014 18:45:02 UTC Severity: normal Tag ...