The dpkg-source command in Debian dpkg before 1.16.16 and 1.17.x before 1.17.25 allows remote attackers to bypass signature verification via a crafted Debian source control file (.dsc).
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0840
Reference (s):
- DEBIAN:DSA-3217
- URL: http://www.debian.org/security/2015/dsa-3217
- FEDORA:FEDORA-2015-6974
- URL: http://lists.fedoraproject.org/pipermail/package-announce/2015-May/157387.html
- SUSE:openSUSE-SU-2015:1058

