VendorsDebiandpkgany version
Vulnerabilities

Debian Dpkg any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

9CVEs
CVE-2022-1664
directory traversal for in-place extracts with untrusted v2 and v3 source packages with debian.tar
Published 2022-05-26 · Modified
9.8EPSS 0.032
CVE-2025-6297
dpkg-deb: Fix cleanup for control member with restricted directories
Published 2025-07-01 · Modified
8.2EPSS 0.004
CVE-2026-2219
It was discovered that dpkg-deb (a component of dpkg, the Debian package management system) does not properly validate the end of the data stream when uncompressing a zstd-compressed .deb archive, which may result in denial of service (infinite loop spinning the CPU).
Published 2026-03-07 · Analyzed
7.5EPSS 0.004
CVE-2014-8625
Multiple format string vulnerabilities in the parse_error_msg function in parsehelp.c in dpkg before 1.17.22 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in the (1) package or (2) architecture name.
Published 2015-01-20 · Modified
6.8EPSS 0.033
CVE-2010-1679
Directory traversal vulnerability in dpkg-source in dpkg before 1.14.31 and 1.15.x allows user-assisted remote attackers to modify arbitrary files via directory traversal sequences in a patch for a source-format 3.0 package.
Published 2011-01-11 · Modified
6.8EPSS 0.031
CVE-2011-0402
dpkg-source in dpkg before 1.14.31 and 1.15.x allows user-assisted remote attackers to modify arbitrary files via a symlink attack on unspecified files in the .pc directory.
Published 2011-01-11 · Modified
6.8EPSS 0.029
CVE-2010-0396
Directory traversal vulnerability in the dpkg-source component in dpkg before 1.14.29 allows remote attackers to modify arbitrary files via a crafted Debian source archive.
Published 2010-03-12 · Modified
5.8EPSS 0.020
CVE-2014-0471
Directory traversal vulnerability in the unpacking functionality in dpkg before 1.15.9, 1.16.x before 1.16.13, and 1.17.x before 1.17.8 allows remote attackers to write arbitrary files via a crafted source package, related to "C-style filename quoting."
Published 2014-04-30 · Modified
5.0EPSS 0.029
CVE-2015-0840
The dpkg-source command in Debian dpkg before 1.16.16 and 1.17.x before 1.17.25 allows remote attackers to bypass signature verification via a crafted Debian source control file (.dsc).
Published 2015-04-13 · Modified
4.3EPSS 0.018