Bug 1199944 (CVE-2022-1664) - VUL-1: CVE-2022-1664: dpkg: dpkg -- security update
Summary: VUL-1: CVE-2022-1664: dpkg: dpkg -- security update
Status: RESOLVED FIXED
Alias: CVE-2022-1664
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P4 - Low : Minor
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/332928/
Whiteboard: CVSSv3.1:SUSE:CVE-2022-1664:4.4:(AV:L...
Keywords:
Depends on:
Blocks:
 
Reported: 2022-05-26 12:59 UTC by Gabriele Sonnu
Modified: 2024-04-19 11:15 UTC (History)
5 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Gabriele Sonnu 2022-05-26 12:59:18 UTC
Max Justicz reported a directory traversal vulnerability in
Dpkg::Source::Archive in dpkg, the Debian package management system.
This affects extracting untrusted source packages in the v2 and v3
source package formats that include a debian.tar.
For the oldstable distribution (buster), this problem has been fixed
in version 1.19.8.
For the stable distribution (bullseye), this problem has been fixed in
version 1.20.10.
We recommend that you upgrade your dpkg packages.
For the detailed security status of dpkg please refer to its security
tracker page at:
https://security-tracker.debian.org/tracker/dpkg

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-1664
http://www.debian.org/security/-1/dsa-5147
Comment 1 Petr Gajdos 2022-05-27 09:35:45 UTC
Submitted for 15/dpkg and 12sp2/dpkg (if something is missing, let me know).
Comment 2 Petr Gajdos 2022-05-27 09:53:25 UTC
Submitted also into devel project:
https://build.opensuse.org/request/show/979458
Comment 4 Petr Gajdos 2022-05-30 08:46:39 UTC
Requests were accepted.
Comment 5 Swamp Workflow Management 2022-08-05 19:17:34 UTC
SUSE-SU-2022:2689-1: An update that fixes one vulnerability is now available.

Category: security (low)
Bug References: 1199944
CVE References: CVE-2022-1664
JIRA References: 
Sources used:
SUSE Linux Enterprise Server 12-SP5 (src):    update-alternatives-1.18.4-16.3.5

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 6 Alexander Bergmann 2022-08-10 11:34:58 UTC
Analysis of the problem in regard of 'dpkg' and 'update-alternatives':

The affected code is inside the Perl implementation of Dpkg::Source::Archive. So only if the Perl module is used the problem exists.

The 'dpkg' command line tool on the other hand is implemented in C and does not inherit the issue in any way. The same goes for the 'update-alternatives' command line tool.
Comment 7 George Kraft 2022-10-11 14:50:32 UTC
What is the bugzilla number for the SLES 15 fix?
Comment 8 Marcus Meissner 2022-11-08 16:22:35 UTC
hi, this is the same bug.

the sles15 fix had various unrelated QA troubles, but these should be resolved soon.
Comment 9 Swamp Workflow Management 2022-11-18 20:25:22 UTC
SUSE-SU-2022:4081-1: An update that fixes one vulnerability is now available.

Category: security (low)
Bug References: 1199944
CVE References: CVE-2022-1664
JIRA References: 
Sources used:
openSUSE Leap Micro 5.3 (src):    update-alternatives-1.19.0.4-150000.4.4.1
openSUSE Leap Micro 5.2 (src):    update-alternatives-1.19.0.4-150000.4.4.1
openSUSE Leap 15.4 (src):    dpkg-1.19.0.4-150000.4.4.1, update-alternatives-1.19.0.4-150000.4.4.1
openSUSE Leap 15.3 (src):    dpkg-1.19.0.4-150000.4.4.1, update-alternatives-1.19.0.4-150000.4.4.1
SUSE Manager Server 4.1 (src):    dpkg-1.19.0.4-150000.4.4.1, update-alternatives-1.19.0.4-150000.4.4.1
SUSE Manager Retail Branch Server 4.1 (src):    dpkg-1.19.0.4-150000.4.4.1, update-alternatives-1.19.0.4-150000.4.4.1
SUSE Manager Proxy 4.1 (src):    dpkg-1.19.0.4-150000.4.4.1, update-alternatives-1.19.0.4-150000.4.4.1
SUSE Linux Enterprise Server for SAP 15-SP2 (src):    dpkg-1.19.0.4-150000.4.4.1, update-alternatives-1.19.0.4-150000.4.4.1
SUSE Linux Enterprise Server for SAP 15-SP1 (src):    dpkg-1.19.0.4-150000.4.4.1, update-alternatives-1.19.0.4-150000.4.4.1
SUSE Linux Enterprise Server for SAP 15 (src):    dpkg-1.19.0.4-150000.4.4.1, update-alternatives-1.19.0.4-150000.4.4.1
SUSE Linux Enterprise Server 15-SP2-LTSS (src):    dpkg-1.19.0.4-150000.4.4.1, update-alternatives-1.19.0.4-150000.4.4.1
SUSE Linux Enterprise Server 15-SP2-BCL (src):    dpkg-1.19.0.4-150000.4.4.1, update-alternatives-1.19.0.4-150000.4.4.1
SUSE Linux Enterprise Server 15-SP1-LTSS (src):    dpkg-1.19.0.4-150000.4.4.1, update-alternatives-1.19.0.4-150000.4.4.1
SUSE Linux Enterprise Server 15-SP1-BCL (src):    dpkg-1.19.0.4-150000.4.4.1, update-alternatives-1.19.0.4-150000.4.4.1
SUSE Linux Enterprise Server 15-LTSS (src):    dpkg-1.19.0.4-150000.4.4.1, update-alternatives-1.19.0.4-150000.4.4.1
SUSE Linux Enterprise Module for Development Tools 15-SP4 (src):    dpkg-1.19.0.4-150000.4.4.1
SUSE Linux Enterprise Module for Development Tools 15-SP3 (src):    dpkg-1.19.0.4-150000.4.4.1
SUSE Linux Enterprise Module for Basesystem 15-SP4 (src):    update-alternatives-1.19.0.4-150000.4.4.1
SUSE Linux Enterprise Module for Basesystem 15-SP3 (src):    update-alternatives-1.19.0.4-150000.4.4.1
SUSE Linux Enterprise Micro 5.3 (src):    update-alternatives-1.19.0.4-150000.4.4.1
SUSE Linux Enterprise Micro 5.2 (src):    update-alternatives-1.19.0.4-150000.4.4.1
SUSE Linux Enterprise Micro 5.1 (src):    update-alternatives-1.19.0.4-150000.4.4.1
SUSE Linux Enterprise High Performance Computing 15-SP2-LTSS (src):    dpkg-1.19.0.4-150000.4.4.1, update-alternatives-1.19.0.4-150000.4.4.1
SUSE Linux Enterprise High Performance Computing 15-SP2-ESPOS (src):    dpkg-1.19.0.4-150000.4.4.1, update-alternatives-1.19.0.4-150000.4.4.1
SUSE Linux Enterprise High Performance Computing 15-SP1-LTSS (src):    dpkg-1.19.0.4-150000.4.4.1, update-alternatives-1.19.0.4-150000.4.4.1
SUSE Linux Enterprise High Performance Computing 15-SP1-ESPOS (src):    dpkg-1.19.0.4-150000.4.4.1, update-alternatives-1.19.0.4-150000.4.4.1
SUSE Linux Enterprise High Performance Computing 15-LTSS (src):    dpkg-1.19.0.4-150000.4.4.1, update-alternatives-1.19.0.4-150000.4.4.1
SUSE Linux Enterprise High Performance Computing 15-ESPOS (src):    dpkg-1.19.0.4-150000.4.4.1, update-alternatives-1.19.0.4-150000.4.4.1
SUSE Enterprise Storage 7 (src):    dpkg-1.19.0.4-150000.4.4.1, update-alternatives-1.19.0.4-150000.4.4.1
SUSE Enterprise Storage 6 (src):    dpkg-1.19.0.4-150000.4.4.1, update-alternatives-1.19.0.4-150000.4.4.1
SUSE CaaS Platform 4.0 (src):    dpkg-1.19.0.4-150000.4.4.1, update-alternatives-1.19.0.4-150000.4.4.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 13 Robert Frohl 2024-04-19 11:15:12 UTC
done