It was reported [1] that dpkg have a format string vulnerability. When building a .deb file using dpkg-deb --build, if the 'control' file inside DEBIAN/ has a % in it, it will segfault. Example of control file and GDB backtrace is available at [1] as well. [1]: https://bugs.launchpad.net/ubuntu/+source/dpkg/+bug/1389135
Created dpkg tracking bugs for this issue: Affects: fedora-all [bug 1162168] Affects: epel-all [bug 1162169]
Note that a second, similar issue was reported to Debian: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=769111
http://anonscm.debian.org/cgit/dpkg/dpkg.git/log/?h=wheezy we still haven't any fix for wheezy . I found commit here : http://anonscm.debian.org/cgit/dpkg/dpkg.git/commit/?id=446f11df6302716c2a1f993761ee54ecb44d42bb says: "Regression introduced in dpkg 1.16.0. Fixes CVE-2014-8625. Closes: #768485" Should I wait a little more ?
dpkg-1.16.16-5.fc22 has been pushed to the Fedora 22 stable repository. If problems still persist, please make note of it in this bug report.
dpkg-1.16.16-5.fc21 has been pushed to the Fedora 21 stable repository. If problems still persist, please make note of it in this bug report.
dpkg-1.16.16-5.fc20 has been pushed to the Fedora 20 stable repository. If problems still persist, please make note of it in this bug report.
dpkg-1.16.16-5.el6 has been pushed to the Fedora EPEL 6 stable repository. If problems still persist, please make note of it in this bug report.
dpkg-1.16.16-5.el7 has been pushed to the Fedora EPEL 7 stable repository. If problems still persist, please make note of it in this bug report.
I couldn't build dpkg for el5 because DEBUG util.py:388: Error: No Package found for po4a [1] [1] https://kojipkgs.fedoraproject.org//work/tasks/5213/9525213/root.log