Lucene search

K
osvGoogleOSV:USN-5446-1
HistoryMay 26, 2022 - 11:16 a.m.

dpkg vulnerability

2022-05-2611:16:17
Google
osv.dev
4

9.3 High

AI Score

Confidence

High

0.009 Low

EPSS

Percentile

82.4%

Max Justicz discovered that dpkg incorrectly handled unpacking certain
source packages. If a user or an automated system were tricked into
unpacking a specially crafted source package, a remote attacker could
modify files outside the target unpack directory, leading to a denial of
service or potentially gaining access to the system.