[WID-SEC-2025-1445] dpkg: Schwachstelle ermöglicht Offenlegung von Informationen CVSS Base Score 8.2 (hoch) CVSS Temporal Score 7.1 (hoch) Remoteangriff ja Datum 01.07.2025 Stand UPDATE 08.07.2026 Mitigation ja Betroffene Systeme Betriebssystem Linux UNIX Produktbeschreibung dpkg ist die Basis der Paketverwaltung verschiedener Linux Distributionen. Produkte UPDATE 07.07.2026 Debian Linux UPDATE 24.09.2025 Ubuntu Linux UPDATE 10.08.2025 SUSE Linux UPDATE 07.07.2025 SUSE openSUSE UPDATE 06.07.2025 Fedora Linux 01.07.2025 Open Source dpkg >=1.20 Open Source dpkg >=1.21 Open Source dpkg >=1.22 Angriff Angriff Ein entfernter, anonymer Angreifer kann eine Schwachstelle in dpkg ausnutzen, um Informationen offenzulegen. CVE Informationen Versionshistorie Feedback zum Advisory geben
A high-severity information disclosure vulnerability (CVSS 8.2) in dpkg allows a remote, anonymous attacker to exploit the package manager to leak sensitive information. The vulnerability affects dpkg versions >=1.20, >=1.21, and >=1.22, impacting major Linux distributions including Debian, Ubuntu, SUSE, openSUSE, and Fedora. Mitigations are available, and users should apply the specific updates provided for their respective distributions.