Unrated severityNVD Advisory· Published Jan 20, 2015· Updated May 6, 2026
CVE-2014-8625
CVE-2014-8625
Description
Multiple format string vulnerabilities in the parse_error_msg function in parsehelp.c in dpkg before 1.17.22 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in the (1) package or (2) architecture name.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- seclists.org/oss-sec/2014/q4/539nvdExploit
- bugs.debian.org/cgi-bin/bugreport.cginvdExploit
- bugs.launchpad.net/ubuntu/+source/dpkg/+bug/1389135nvdExploit
- lists.fedoraproject.org/pipermail/package-announce/2015-May/157387.htmlnvd
- seclists.org/oss-sec/2014/q4/551nvd
- seclists.org/oss-sec/2014/q4/622nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/98551nvd
News mentions
0No linked articles in our index yet.