dpkg: Directory Traversal A vulnerability has been discovered in dpkg, which allows for directory traversal. dpkg 2024-08-12 2024-08-12 847976 local 1.20.9-r1 1.20.9-r1

Debian package management system.

Please review the CVE indentifier referenced below for details.

Dpkg::Source::Archive in dpkg, the Debian package management system, is prone to a directory traversal vulnerability. When extracting untrusted source packages in v2 and v3 source package formats that include a debian.tar, the in-place extraction can lead to directory traversal situations on specially crafted orig.tar and debian.tar tarballs.

There is no known workaround at this time.

All dpkg users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=app-arch/dpkg-1.20.9-r1"
CVE-2022-1664 graaff graaff