Description
Multiple format string vulnerabilities in the parse_error_msg function in parsehelp.c in dpkg before 1.17.22 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in the (1) package or (2) architecture name.
References (7)
Scores
EPSS
0.0246
EPSS Percentile
85.3%
Details
CWE
CWE-134
Status
published
Products (1)
debian/dpkg
< 1.17.21
Published
Jan 20, 2015
Tracked Since
Feb 18, 2026