CVE-2022-1664
Summary
| CVE | CVE-2022-1664 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-05-26 14:15:00 UTC |
| Updated | 2022-12-03 02:19:00 UTC |
| Description | Dpkg::Source::Archive in dpkg, the Debian package management system, before version 1.21.8, 1.20.10, 1.19.8, 1.18.26 is prone to a directory traversal vulnerability. When extracting untrusted source packages in v2 and v3 source package formats that include a debian.tar, the in-place extraction can lead to directory traversal situations on specially crafted orig.tar and debian.tar tarballs. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| dpkg/dpkg.git - Debian package management system |
MISC |
git.dpkg.org |
|
| dpkg/dpkg.git - Debian package management system |
MISC |
git.dpkg.org |
|
| dpkg/dpkg.git - Debian package management system |
MISC |
git.dpkg.org |
|
| [SECURITY] [DLA 3022-1] dpkg security update |
MISC |
lists.debian.org |
|
| [SECURITY] [DSA 5147-1] dpkg security update |
MISC |
lists.debian.org |
|
| CVE-2022-1664 Dpkg Vulnerability in NetApp Products | NetApp Product Security |
CONFIRM |
security.netapp.com |
|
| dpkg/dpkg.git - Debian package management system |
MISC |
git.dpkg.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 179314 Debian Security Update for dpkg (DLA 3022-1)
- 179316 Debian Security Update for dpkg (DSA 5147-1)
- 183195 Debian Security Update for dpkg (CVE-2022-1664)
- 198805 Ubuntu Security Notification for dpkg Vulnerability (USN-5446-1)
- 501398 Alpine Linux Security Update for dpkg
- 502214 Alpine Linux Security Update for dpkg
- 503901 Alpine Linux Security Update for dpkg
- 672029 EulerOS Security Update for dpkg (EulerOS-SA-2022-2219)
- 752447 SUSE Enterprise Linux Security Update for dpkg (SUSE-SU-2022:2689-1)
- 752859 SUSE Enterprise Linux Security Update for dpkg (SUSE-SU-2022:4081-1)
- 902141 Common Base Linux Mariner (CBL-Mariner) Security Update for dpkg (9853)
- 902388 Common Base Linux Mariner (CBL-Mariner) Security Update for dpkg (9853-1)