Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

Ubuntu 16.04 ESM USN-5446-2 Moderate: dpkg File Access Threat

Ubuntu Large Esm H500
A malicious source package could write files outside the unpack directory.
=========================================================================Ubuntu Security Notice USN-5446-2
May 30, 2022

dpkg vulnerability
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 16.04 ESM

Summary:

A malicious source package could write files outside the unpack directory.

Software Description:
- dpkg: Debian package management system

Details:

USN-5446-1 fixed a vulnerability in dpkg. This update provides
the corresponding update for Ubuntu 16.04 ESM.

Original advisory details:

 Max Justicz discovered that dpkg incorrectly handled unpacking certain
 source packages. If a user or an automated system were tricked into
 unpacking a specially crafted source package, a remote attacker could
 modify files outside the target unpack directory, leading to a denial of
 service or potentially gaining access to the system.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 16.04 ESM:
  dpkg                            1.18.4ubuntu1.7+esm1
  libdpkg-perl                    1.18.4ubuntu1.7+esm1

In general, a standard system update will make all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-5446-2
  https://ubuntu.com/security/notices/USN-5446-1
  CVE-2022-1664

Ubuntu 16.04 ESM USN-5446-2 Moderate: dpkg File Access Threat

ubuntu
Calendar Grey May 30, 2022
Dist Ubuntu Esm H88
Mitigating dpkg security flaw in Ubuntu 16.04 ESM which enables adversarial packages to modify files beyond the designated unpack area.
A malicious source package could write files outside the unpack directory.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 ESM: dpkg 1.18.4ubuntu1.7+esm1 libdpkg-perl 1.18.4ubuntu1.7+esm1 In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-5446-2

https://ubuntu.com/security/notices/USN-5446-1

CVE-2022-1664

May 30, 2022

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here