Logo
vulnerabilityCVE-2022-1664
Name
CVE-2022-1664
Source
NVD ( link)Debian ( link)
Description
Dpkg::Source::Archive in dpkg, the Debian package management system, before version 1.21.8, 1.20.10, 1.19.8, 1.18.26 is prone to a directory traversal vulnerability. When extracting untrusted source packages in v2 and v3 source package formats that include a debian.tar, the in-place extraction can lead to directory traversal situations on specially crafted orig.tar and debian.tar tarballs.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
dpkg
Patched

Vulnerability Ratings#


9.8
CVSSv31
7.5
CVSSv2

Others affected components#


Name
Project
Project Version
Version
Status
yocto
master
1.23.7
Not Affected
yocto
scarthgap
1.22.0
Not Affected

Resolved with patches#


dpkg (yocto:kirkstone)

#
Title
Author
Resolve
1
Dpkg::Source::Archive: Prevent directory traversal for
Guillem Jover <guillem@debian.org>
CVE-2022-1664