CVE-2022-1664

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
26/05/2022
Last modified:
03/12/2022

Description

Dpkg::Source::Archive in dpkg, the Debian package management system, before version 1.21.8, 1.20.10, 1.19.8, 1.18.26 is prone to a directory traversal vulnerability. When extracting untrusted source packages in v2 and v3 source package formats that include a debian.tar, the in-place extraction can lead to directory traversal situations on specially crafted orig.tar and debian.tar tarballs.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:debian:dpkg:*:*:*:*:*:*:*:* 1.14.17 (including) 1.18.26 (excluding)
cpe:2.3:a:debian:dpkg:*:*:*:*:*:*:*:* 1.19.0 (including) 1.19.8 (excluding)
cpe:2.3:a:debian:dpkg:*:*:*:*:*:*:*:* 1.20.0 (including) 1.20.10 (excluding)
cpe:2.3:a:debian:dpkg:*:*:*:*:*:*:*:* 1.21.0 (including) 1.21.8 (excluding)
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
cpe:2.3:a:netapp:ontap_select_deploy_administration_utility:-:*:*:*:*:*:*:*