{"id":"CVE-2022-1664","summary":"directory traversal for in-place extracts with untrusted v2 and v3 source packages with debian.tar","details":"Dpkg::Source::Archive in dpkg, the Debian package management system, before version 1.21.8, 1.20.10, 1.19.8, 1.18.26 is prone to a directory traversal vulnerability. When extracting untrusted source packages in v2 and v3 source package formats that include a debian.tar, the in-place extraction can lead to directory traversal situations on specially crafted orig.tar and debian.tar tarballs.","modified":"2026-08-12T03:51:28.796746434Z","published":"2022-05-26T08:20:15.198Z","related":["SUSE-SU-2022:2689-1","SUSE-SU-2022:4081-1","openSUSE-SU-2024:12110-1"],"database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/1xxx/CVE-2022-1664.json","cna_assigner":"debian"},"references":[{"type":"WEB","url":"https://git.dpkg.org/cgit/dpkg/dpkg.git/commit/?id=1f23dddc17f69c9598477098c7fb9936e15fa495"},{"type":"WEB","url":"https://git.dpkg.org/cgit/dpkg/dpkg.git/commit/?id=58814cacee39c4ce9e2cd0e3a3b9b57ad437eff5"},{"type":"WEB","url":"https://git.dpkg.org/cgit/dpkg/dpkg.git/commit/?id=7a6c03cb34d4a09f35df2f10779cbf1b70a5200b"},{"type":"WEB","url":"https://git.dpkg.org/cgit/dpkg/dpkg.git/commit/?id=faa4c92debe45412bfcf8a44f26e827800bb24be"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2022/05/msg00033.html"},{"type":"WEB","url":"https://lists.debian.org/debian-security-announce/2022/msg00115.html"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/1xxx/CVE-2022-1664.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-1664"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20221007-0002/"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.dpkg.org/cgit/dpkg/dpkg.git","events":[{"introduced":"47d2e9c479d6650e4980231606cd43c744e3c0c9"},{"fixed":"e195a9f2ffd547e332f8f148a4135f537a5e77e7"},{"introduced":"90d2887c67f2b1d0915169cc49725bb774083aba"},{"fixed":"99902811cf1b1f41eed3bce2fc7ab8a4f02c364b"},{"introduced":"314ac02663c5bd1a82b34745150bf13a39a549a3"},{"fixed":"6247c7c3da135b41ac94af82e0b739cb40ba595d"},{"introduced":"1f4238aba8850f83280ca88e14c7b48ee7e07d7e"},{"fixed":"a154134fe70c0b823ae14905bdc33b64e7dcd454"},{"fixed":"1f23dddc17f69c9598477098c7fb9936e15fa495"},{"fixed":"58814cacee39c4ce9e2cd0e3a3b9b57ad437eff5"},{"fixed":"7a6c03cb34d4a09f35df2f10779cbf1b70a5200b"},{"fixed":"faa4c92debe45412bfcf8a44f26e827800bb24be"}],"database_specific":{"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:debian:dpkg:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"1.14.17"},{"fixed":"1.18.26"},{"introduced":"1.19.0"},{"fixed":"1.19.8"},{"introduced":"1.20.0"},{"fixed":"1.20.10"},{"introduced":"1.21.0"},{"fixed":"1.21.8"}]}}],"versions":["1.21.7","1.21.6","1.21.5","1.21.4","1.21.3","1.21.2","1.21.1","1.21.0","1.20.9","1.20.8","1.20.7","1.20.6","1.20.5","1.20.4","1.20.3","1.20.2","1.20.1","1.20.0","1.19.7","1.18.25","1.19.6","1.19.5","1.19.4","1.19.3","1.19.2","1.19.1","1.18.24","1.19.0","1.18.23","1.18.22","1.18.21","1.18.20","1.18.19","1.18.18","1.18.17","1.18.16","1.18.15","1.18.14","1.18.13","1.18.12","1.18.11","1.18.10","1.18.9","1.18.8","1.18.7","1.18.6","1.18.5","1.18.4","1.18.3","1.18.2","1.18.1","1.18.0","1.17.23","1.17.22","1.17.21","1.17.20","1.17.19","1.17.18","1.17.17","1.17.16","1.17.15","1.17.14","1.17.13","1.17.12","1.17.11","1.17.10","1.17.9","1.17.8","1.17.7","1.17.6","1.17.5","1.17.4","1.17.3","1.17.2","1.17.1","1.17.0","1.16.10","1.16.6","1.16.5","1.16.4","1.16.3","1.16.2","1.16.1","1.16.0","1.15.8","1.15.7","1.15.6.1","1.15.6","1.15.5.1","1.15.5","1.15.4","1.15.3","1.15.2","1.15.1","1.15.0","1.14.18","1.14.17"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-1664.json"}}],"schema_version":"1.9.0"}