OESA-2022-1703
Dashboard / Vulnerabilities / OESA-2022-1703
Summary: dpkg security update
Details: Dpkg is a tool to install, build, remove and manageDebian packages. The primary and more user-friendly front-end for dpkg is aptitude. Security Fix(es): Dpkg::Source::Archive in dpkg, the Debian package management system, before version 1.21.8, 1.20.10, 1.19.8, 1.18.26 is prone to a directory traversal vulnerability. When extracting untrusted source packages in v2 and v3 source package formats that include a debian.tar, the in-place extraction can lead to directory traversal situations on specially crafted orig.tar and debian.tar tarballs.(CVE-2022-1664)
References: https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2022-1703, https://nvd.nist.gov/vuln/detail/CVE-2022-1664
Affected packages
Package
Name: dpkg
Purl: pkg:rpm/openEuler/dpkg&distro=openEuler-20.03-LTS-SP1
Affected ranges
Type: ECOSYSTEM
Events:
