ELA-631-1 dpkg security update

directory traversal vulnerability

2022-07-03
Packagedpkg
Version1.17.28 (jessie)
Related CVEs CVE-2022-1664


Max Justicz reported a directory traversal vulnerability in Dpkg::Source::Archive in dpkg, the Debian package management system. This affects extracting untrusted source packages in the v2 and v3 source package formats that include a debian.tar.



For Debian 8 jessie, these problems have been fixed in version 1.17.28.

We recommend that you upgrade your dpkg packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.