SUSE-SU-2017:1096-1
Dashboard / Vulnerabilities / SUSE-SU-2017:1096-1
SUSE-SU-2017:1096-1
Summary: Security update for dpkg
Details: This update for dpkg fixes the following issues: This security issue was fixed: - CVE-2015-0860: Off-by-one error in the extracthalf function in dpkg-deb/extract.c in the dpkg-deb component in dpkg allowed remote attackers to execute arbitrary code via the archive magic version number in an 'old-style' Debian binary package, which triggered a stack-based buffer overflow (bsc#957160).
References: https://www.suse.com/support/update/announcement/2017/suse-su-20171096-1/, https://bugzilla.suse.com/957160, https://www.suse.com/security/cve/CVE-2015-0860
Affected packages
Package
Name: update-alternatives
Purl: pkg:rpm/suse/update-alternatives&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP1
Affected ranges
Type: ECOSYSTEM
Events:
