Univention Bugzilla – Bug 38243
dpkg: Multiple issues (4.0)
Last modified: 2015-09-15 13:36:46 CEST
CVE-2015-0840 Incorrect signature validation when extracting local source packages.
Fixed in upstream Debian package version 1.16.16
dpkg 1.16.16 was imported and build to scope errata4.0-3. YAML (r63393): 2015-09-01-dpkg.yaml
OK: DEBIAN_FRONTEND=noninteractive aptitude -y install '?source-package(^dpkg$)~i' OK: DEBIAN_FRONTEND=noninteractive aptitude -y install '?source-package(^dpkg$)?not(?name(udeb))' OK: zless /usr/share/doc/dpkg/changelog.Debian.gz OK: bzgrep 700_Dpkg_Control.t logs/ucs_4.0-0-0-errata4.0-3/dpkg_1.16.16.95.201509011754.log* OK: DPKG_ORIGINS_DIR=./t/origins PERL_DL_NONLAZY=1 /usr/bin/perl -MExtUtils::Command::MM -e "test_harness(0, '.')" t/700_Dpkg_Control.t OK: r63393 OK: 2015-09-01-dpkg.yaml OK: errata-announce -V 2015-09-01-dpkg.yaml
<http://errata.software-univention.de/ucs/4.0/315.html>