Ubuntu Security Notices USN-8109-1 USN-8109-1: Debian Goodies vulnerability Publication date 18 March 2026 Overview Debian Goodies could be made to crash or run programs as your login if it opened a specially crafted file. Releases 24.04 LTS 18.04 LTS 16.04 LTS 14.04 LTS Open side navigation Close side navigation Packages Details Update instructions References Related notices Packages debian-goodies - Small toolbox-style utilities for Debian systems Details Jakub Wilk discovered that debmany in Debian Goodies incorrectly handled certain deb files. An attacker could possibly use this issue to execute arbitrary shell commands. Jakub Wilk discovered that debmany in Debian Goodies incorrectly handled certain deb files. An attacker could possibly use this issue to execute arbitrary shell commands. Update instructions In general, a standard system update will make all the necessary changes. Learn more about how to get the fixes. The problem can be corrected by updating your system to the following package versions: Ubuntu Release Package Version 24.04 LTS noble debian-goodies – 0.88.1ubuntu1.3 18.04 LTS bionic debian-goodies – 0.79ubuntu0.1~esm1 Ubuntu Pro Fix available with Ubuntu Pro . 16.04 LTS xenial debian-goodies – 0.64ubuntu0.1~esm1 Ubuntu Pro Fix available with Ubuntu Pro . 14.04 LTS trusty debian-goodies – 0.63ubuntu1+esm1 Ubuntu Pro Fix available with Ubuntu Pro via Legacy Support add-on. Reduce your security exposure Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines. Get Ubuntu Pro References CVE-2023-27635 CVE-2023-27635 Related notices USN-6714-1 USN-6714-1
A vulnerability (CVE-2023-27635, CVSS 7.8 HIGH) in the `debmany` utility of the Debian Goodies package allows an attacker to execute arbitrary shell commands by tricking a user into opening a specially crafted `.deb` file. The affected version is debian-goodies 0.88.1. The issue is corrected by updating to debian-goodies version 0.88.1ubuntu1.3 for Ubuntu 24.04 LTS, with specific patched versions also listed for older, extended support releases.