UBUNTU-CVE-2022-1664
Dashboard / Vulnerabilities / UBUNTU-CVE-2022-1664
UBUNTU-CVE-2022-1664
Summary:
Details: Dpkg::Source::Archive in dpkg, the Debian package management system, before version 1.21.8, 1.20.10, 1.19.8, 1.18.26 is prone to a directory traversal vulnerability. When extracting untrusted source packages in v2 and v3 source package formats that include a debian.tar, the in-place extraction can lead to directory traversal situations on specially crafted orig.tar and debian.tar tarballs.
References: https://ubuntu.com/security/CVE-2022-1664, https://ubuntu.com/security/notices/USN-5446-1, https://ubuntu.com/security/notices/USN-5446-2, https://www.cve.org/CVERecord?id=CVE-2022-1664
Affected packages
Package
Name: dpkg
Purl: pkg:deb/ubuntu/[email protected]+esm1?arch=source&distro=esm-infra-legacy/trusty
Affected ranges
Type: ECOSYSTEM
Events:
