Path traversal in dpkg - CVE-2022-1664

 

Path traversal in dpkg - CVE-2022-1664

Published: May 26, 2022


Vulnerability identifier: #VU63711
CSH Severity: Medium
CVSS v4: 7.4 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-1664
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform directory traversal attacks.

The vulnerability exists due to input validation error in Dpkg::Source::Archive in dpkg when extracting untrusted source packages in the v2 and v3 source package formats that include a debian.tar. A remote attacker can create a specially crafted package with symbolic links that point to files outside the source tree root directory and overwrite arbitrary files on the system.


Affected software

dpkg
cflinuxfs3
Platform Automation Toolkit
Dell Data Protection Central
Gentoo Linux
SUSE CaaS Platform
SUSE Manager Server
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Linux Enterprise Micro
openSUSE Leap Micro
SUSE Enterprise Storage
SUSE Linux Enterprise Server
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Module for Development Tools
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Module for Basesystem
openSUSE Leap
Ubuntu
openEuler
libdpkg-perl (Ubuntu package)
dpkg (Ubuntu package)
update-alternatives-debugsource
update-alternatives-debuginfo
update-alternatives
dpkg-perl
dpkg
dpkg-debuginfo
dpkg-help
dpkg-devel
dpkg-debugsource
dpkg-lang
dpkg (Debian package)
app-arch/dpkg
Isolation Segment
VMware Tanzu Application Service for VMs
Dell EMC VxRail Appliance

How to mitigate CVE-2022-1664

Install update from vendor's website.

dpkg - addressed in versions 1.18.26, 1.19.8, 1.20.10, 1.21.8
cflinuxfs3 - update to 0.301.0
libdpkg-perl (Ubuntu package) - addressed in versions 1.18.4ubuntu1.7+esm1, 1.19.0.5ubuntu2.4, 1.19.7ubuntu3.2, 1.20.9ubuntu2.2, 1.21.1ubuntu2.1
dpkg (Ubuntu package) - addressed in versions 1.18.4ubuntu1.7+esm1, 1.19.0.5ubuntu2.4, 1.19.7ubuntu3.2, 1.20.9ubuntu2.2, 1.21.1ubuntu2.1
update-alternatives-debugsource - addressed in versions 1.18.4-16.3.5, 1.19.0.4-150000.4.4.1
update-alternatives-debuginfo - addressed in versions 1.18.4-16.3.5, 1.19.0.4-150000.4.4.1
update-alternatives - addressed in versions 1.18.4-16.3.5, 1.19.0.4-150000.4.4.1
dpkg-perl - update to 1.18.25-11
dpkg - update to 1.18.25-11
dpkg-debuginfo - update to 1.18.25-11
dpkg-help - update to 1.18.25-11
dpkg-devel - update to 1.18.25-11
dpkg-debugsource - update to 1.18.25-11
dpkg-lang - update to 1.19.0.4-150000.4.4.1
dpkg-devel - update to 1.19.0.4-150000.4.4.1
dpkg-debugsource - update to 1.19.0.4-150000.4.4.1
dpkg-debuginfo - update to 1.19.0.4-150000.4.4.1
dpkg - update to 1.19.0.4-150000.4.4.1
dpkg (Debian package) - addressed in versions 1.19.8, 1.20.10
app-arch/dpkg - update to 1.20.9-r1
Isolation Segment - addressed in versions 2.7.45, 2.10.25, 2.11.14, 2.12.10
VMware Tanzu Application Service for VMs - addressed in versions 2.7.50, 2.10.32, 2.11.20, 2.12.15, 2.13.5
Platform Automation Toolkit - addressed in versions 4.4.29, 5.0.22
Dell EMC VxRail Appliance - update to 7.0.411
Dell Data Protection Central - update to 19.7.0-9

External References

Related Security Bulletins