Comment 4 for bug 1389135

Revision history for this message
Joshua Rogers (megamansec) wrote :

I don't have the time/skill to try, but I'm guessing that if you can somehow actually build the package with that set as the architecture, unpacking the .deb file will also be vulnerable, which would defintley be a security-related bug.

My guess is that it _does_ exist in the unpacking phase too, since the bug seems to be triggered in lib/dpkg/parsehelp.c.