Dpkg::Source::Archive in dpkg, the Debian package management system, before version 1.21.8, 1.20.10, 1.19.8, 1.18.26 is prone to a directory traversal vulnerability. When extracting untrusted source packages in v2 and v3 source package formats that include a debian.tar, the in-place extraction can lead to directory traversal situations on specially crafted orig.tar and debian.tar tarballs.
{ "availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "1.18.4ubuntu1.7+esm1", "binary_name": "dpkg" }, { "binary_version": "1.18.4ubuntu1.7+esm1", "binary_name": "dpkg-dbgsym" }, { "binary_version": "1.18.4ubuntu1.7+esm1", "binary_name": "dpkg-dev" }, { "binary_version": "1.18.4ubuntu1.7+esm1", "binary_name": "dselect" }, { "binary_version": "1.18.4ubuntu1.7+esm1", "binary_name": "dselect-dbgsym" }, { "binary_version": "1.18.4ubuntu1.7+esm1", "binary_name": "libdpkg-dev" }, { "binary_version": "1.18.4ubuntu1.7+esm1", "binary_name": "libdpkg-perl" } ] }
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "1.19.0.5ubuntu2.4", "binary_name": "dpkg" }, { "binary_version": "1.19.0.5ubuntu2.4", "binary_name": "dpkg-dbgsym" }, { "binary_version": "1.19.0.5ubuntu2.4", "binary_name": "dpkg-dev" }, { "binary_version": "1.19.0.5ubuntu2.4", "binary_name": "dselect" }, { "binary_version": "1.19.0.5ubuntu2.4", "binary_name": "dselect-dbgsym" }, { "binary_version": "1.19.0.5ubuntu2.4", "binary_name": "libdpkg-dev" }, { "binary_version": "1.19.0.5ubuntu2.4", "binary_name": "libdpkg-perl" } ] }
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "1.19.7ubuntu3.2", "binary_name": "dpkg" }, { "binary_version": "1.19.7ubuntu3.2", "binary_name": "dpkg-dbgsym" }, { "binary_version": "1.19.7ubuntu3.2", "binary_name": "dpkg-dev" }, { "binary_version": "1.19.7ubuntu3.2", "binary_name": "dselect" }, { "binary_version": "1.19.7ubuntu3.2", "binary_name": "dselect-dbgsym" }, { "binary_version": "1.19.7ubuntu3.2", "binary_name": "libdpkg-dev" }, { "binary_version": "1.19.7ubuntu3.2", "binary_name": "libdpkg-perl" } ] }
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "1.21.1ubuntu2.1", "binary_name": "dpkg" }, { "binary_version": "1.21.1ubuntu2.1", "binary_name": "dpkg-dbgsym" }, { "binary_version": "1.21.1ubuntu2.1", "binary_name": "dpkg-dev" }, { "binary_version": "1.21.1ubuntu2.1", "binary_name": "dselect" }, { "binary_version": "1.21.1ubuntu2.1", "binary_name": "dselect-dbgsym" }, { "binary_version": "1.21.1ubuntu2.1", "binary_name": "libdpkg-dev" }, { "binary_version": "1.21.1ubuntu2.1", "binary_name": "libdpkg-perl" } ] }