==========================================================================
Ubuntu Security Notice USN-2242-1
June 10, 2014
dpkg vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
– Ubuntu 14.04 LTS
– Ubuntu 13.10
– Ubuntu 12.04 LTS
– Ubuntu 10.04 LTS
Summary:
A malicious source package could write files outside the unpack directory.
Software Description:
– dpkg: Debian package management system
Details:
It was discovered that dpkg incorrectly handled certain patches when
unpacking source packages. If a user or an automated system were tricked
into unpacking a specially crafted source package, a remote attacker could
modify files outside the target unpack directory, leading to a denial of
service or potentially gaining access to the system.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 14.04 LTS:
libdpkg-perl 1.17.5ubuntu5.3
Ubuntu 13.10:
libdpkg-perl 1.16.12ubuntu1.3
Ubuntu 12.04 LTS:
libdpkg-perl 1.16.1.2ubuntu7.5
Ubuntu 10.04 LTS:
dpkg-dev 1.15.5.6ubuntu4.9
In general, a standard system update will make all the necessary changes.
References:
http://www.ubuntu.com/usn/usn-2242-1
CVE-2014-3864, CVE-2014-3865
Package Information:
https://launchpad.net/ubuntu/+source/dpkg/1.17.5ubuntu5.3
https://launchpad.net/ubuntu/+source/dpkg/1.16.12ubuntu1.3
https://launchpad.net/ubuntu/+source/dpkg/1.16.1.2ubuntu7.5
https://launchpad.net/ubuntu/+source/dpkg/1.15.5.6ubuntu4.9
—–BEGIN PGP SIGNATURE—–
Version: GnuPG v1
Comment: Using GnuPG with Thunderbird – http://www.enigmail.net/
iQIcBAEBCgAGBQJTlvRiAAoJEGVp2FWnRL6TRKMQAKGhX1DiScrxkzKCO4yTXVqP
KrjDnU20hQ3YxjhJG32iZqFkufFZ11rZeHzNfNxFXcVtWej5+CAlixV5Dnr1Qm11
0IalBAghRemlTLSPSh6zQ3nUD+RS/8fuM/uvJHfuOeyFLKYPCvM572xurNm5dVgJ
3/JJ+nM3siZzfu7IXov14f8QFIuQfwcCuFG2wMqjMZMx2yoigjZE4pn0l1QPw63k
duRZh99V6FFlmyeVzGahU0+94LskrjAp2Eb9QjeYXWvrSP92dr66H4WTVQscWy34
QQeexMsN1MY8Q3I9rNwhGRhvkHP7LzrYqY39KD12ao0hZad8ABKU6NducaRr/ZhV
gPbQtHuDe65YFwlBeTSYcGgsr5fYSVSaxObQHJz440oO6+c1QkNoRJQsl4/vLUxl
W7J6MWuvB9KYcVS8XjvqFRw7evf6GhSFIWYFHSEC+ul1uzA16NL1FLuoTdSQSCcv
Germ1gh0sKgTyAV5K6pWHXNBA4boxXw8oCXt7s6vOb7/HI/JPX01RSdgaRo8zGT+
o52uPO+IEhzhbd7WM4lKGYZ/1vI9dpFj7ambNWCo2cNl3s/d64yQMMuobdOU23iA
p9E4eE/dWslivqXsvhOWtDCDmplgkPq7g1JRQ3lnh5x2WPysnc6NDEWn/RM+gX0e
Vazk1xQ2lPg+IGMsFQL8
=tIsz
—–END PGP SIGNATURE—–
—