CVE-2015-0840: Canonical Ubuntu Linux

Medium severity, CVSS 4.3. EPSS: 1.8% chance of exploitation in the next 30 days.

The dpkg-source command in Debian dpkg before 1.16.16 and 1.17.x before 1.17.25 allows remote attackers to bypass signature verification via a crafted Debian source control file (.dsc).

Affected products

  • Canonical Ubuntu Linux: version 10.04 only; version 12.04 only; version 14.04 only; version 14.10 only
  • Debian Dpkg: up to and including 1.16.15; version 1.17.0 only; version 1.17.1 only; version 1.17.2 only; version 1.17.3 only; version 1.17.4 only; …

Published 2015-04-13. Last modified 2026-06-17.