PT-2022-4834 · Debian+5 · Dpkg+5

Max Justicz

·

Published

2022-05-25

·

Updated

2026-03-28

·

CVE-2022-1664

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions dpkg versions prior to 1.21.8 dpkg versions prior to 1.20.10 dpkg versions prior to 1.19.8 dpkg versions prior to 1.18.26
Description The issue is related to a directory traversal vulnerability in the Dpkg::Source::Archive component of the Debian package management system. This vulnerability can be exploited by a remote attacker to access confidential data, compromise data integrity, and cause a denial of service. The vulnerability occurs when extracting untrusted source packages in v2 and v3 source package formats that include a debian.tar, leading to directory traversal situations on specially crafted orig.tar and debian.tar tarballs.
Recommendations For versions prior to 1.21.8, update to version 1.21.8 or later. For versions prior to 1.20.10, update to version 1.20.10 or later. For versions prior to 1.19.8, update to version 1.19.8 or later. For versions prior to 1.18.26, update to version 1.18.26 or later.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

ALT-PU-2022-2097
ALT-PU-2023-2049
ALT-PU-2025-13296
AZL-9853
BDU:2022-05892
CVE-2022-1664
DLA-3022-1
DSA-5147-1
MGASA-2022-0327
OESA-2022-1703
OPENSUSE-SU-2022_4081-1
OPENSUSE-SU-2024:12110-1
SUSE-SU-2022:2689-1
SUSE-SU-2022:4081-1
SUSE-SU-2022_2689-1
SUSE-SU-2022_4081-1
USN-5446-1
USN-5446-2

Affected Products

Alt Linux
Astra Linux
Linuxmint
Suse
Ubuntu
Dpkg