CVE-2015-0840
dpkg - security update
EPSS 0.74%
Description
The dpkg-source command in Debian dpkg before 1.16.16 and 1.17.x before 1.17.25 allows remote attackers to bypass signature verification via a crafted Debian source control file (.dsc).
How to fix CVE-2015-0840
To remediate CVE-2015-0840, upgrade the affected package to a fixed version below.
- Debian/dpkg—upgrade to 1.17.25 or later
- Debian/dpkg—upgrade to 1.15.12 or later
- Debian/dpkg—upgrade to 1.16.16 or later
Is CVE-2015-0840 being exploited?
Low — EPSS is 0.7%, meaning exploitation activity has not been observed at scale.
Affected packages (3)
- from 0, < 1.17.25
- from 0, < 1.15.12
- from 0, < 1.16.16