Dpkg::Source::Archive in dpkg, the Debian package management system, before version 1.21.8, 1.20.10, 1.19.8, 1.18.26 is prone to a directory traversal vulnerability. When extracting untrusted source packages in v2 and v3 source package formats that include a debian.tar, the in-place extraction can lead to directory traversal situations on specially crafted orig.tar and debian.tar tarballs.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | alpine-linux-upgrade-dpkg | Mar 26, 2024 | May 26, 2022 | |
| Debian | debian-upgrade-dpkg | May 27, 2022 | May 27, 2022 | |
| Dell Powerstore Dsa2023366 | dell-powerstoreos-upgrade-latest | Oct 23, 2025 | Oct 5, 2023 | |
| Gentoo Linux | gentoo-linux-upgrade-app-arch-dpkg | Aug 13, 2024 | May 26, 2022 | |
| Huawei Euleros 2_0_sp8 | huawei-euleros-2_0_sp8-upgrade-dpkg | Aug 18, 2022 | May 26, 2022 | |
| Suse | — | suse-upgrade-dpkgsuse-upgrade-dpkg-develsuse-upgrade-dpkg-lang | Nov 21, 2022 | May 26, 2022 |
| Ubuntu | ubuntu-pro-upgrade-dpkgubuntu-pro-upgrade-libdpkg-perlubuntu-upgrade-dpkgubuntu-upgrade-libdpkg-perl | May 31, 2022 | May 26, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub