Dpkg::Source::Archive in dpkg, the Debian package management system, before version 1.21.8, 1.20.10, 1.19.8, 1.18.26 is prone to a directory traversal vulnerability. When extracting untrusted source packages in v2 and v3 source package formats that include a debian.tar, the in-place extraction can lead to directory traversal situations on specially crafted orig.tar and debian.tar tarballs.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade dpkg | Mar 26, 2024 | May 26, 2022 |
| Debian | — | Upgrade dpkg | May 27, 2022 | May 27, 2022 |
| Dell Powerstore Dsa2023366 | — | Upgrade Dell PowerStoreOS to the latest version | Oct 23, 2025 | Oct 5, 2023 |
| Gentoo Linux | — | Upgrade app-arch/dpkg. | Aug 13, 2024 | May 26, 2022 |
| Huawei Euleros 2_0_sp8 | — | Upgrade dpkg | Aug 18, 2022 | May 26, 2022 |
| Suse | — | Upgrade dpkg-develUpgrade dpkg-langUpgrade dpkg | Nov 21, 2022 | May 26, 2022 |
| Ubuntu | — | Upgrade libdpkg-perl (Ubuntu Pro)Upgrade dpkg (Ubuntu Pro)Upgrade dpkgUpgrade libdpkg-perl | May 31, 2022 | May 26, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub