← Vulnerability feed

Vulnerability record · CVE-2017-8283 · published 26 April 2017

CVE-2017-8283: Debian dpkg path traversal vulnerability

Debian · Dpkg

dpkg-source in dpkg 1.3.0 through 1.18.23 is able to use a non-GNU patch program and does not offer a protection mechanism for blank-indented diff hunks, which allows remote attackers to conduct directory traversal attacks via a crafted Debian source package, as demonstrated by use of dpkg-source on NetBSD.

9.8 CVSS 3.0 Critical EPSS 4.6% · top 8.6% CWE-22 · Path traversal
9.8CVSS 3.0 base score, v2 7.5
4.6%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

dpkg-source in dpkg 1.3.0 through 1.18.23 is able to use a non-GNU patch program and does not offer a protection mechanism for blank-indented diff hunks, which allows remote attackers to conduct directory traversal attacks via a crafted Debian source package, as demonstrated by use of dpkg-source on NetBSD.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://www.openwall.com/lists/oss-security/2017/04/20/2 Mailing ListPatchThird Party Advisory
http://www.securityfocus.com/bid/98064 Third Party AdvisoryVDB Entry
http://www.openwall.com/lists/oss-security/2017/04/20/2 Mailing ListPatchThird Party Advisory
http://www.securityfocus.com/bid/98064 Third Party AdvisoryVDB Entry

Track CVE-2017-8283 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-1664Debian dpkg path traversal vulnerabilityDpkg::Source::Archive in dpkg, the Debian package management system, before version 1.21.8, 1.20.10, 1.19.8, 1.18.26 is prone to a directory traversa…EPSS 3.2%8.2CVE-2025-6297Debian dpkg uncontrolled resource consumption vulnerabilityIt was discovered that dpkg-deb does not properly sanitize directory permissions when extracting a control member into a temporary directory, which i…EPSS 0.38%7.5CVE-2026-2219Debian dpkg vulnerabilityIt was discovered that dpkg-deb (a component of dpkg, the Debian package management system) does not properly validate the end of the data stream whe…EPSS 0.42%7.5CVE-2015-0860Canonical ubuntu linux vulnerabilityOff-by-one error in the extracthalf function in dpkg-deb/extract.c in the dpkg-deb component in Debian dpkg 1.16.x before 1.16.17 and 1.17.x before 1…EPSS 5.0%7.2CVE-2004-2768Debian dpkg permissions and access controls vulnerabilitydpkg 1.9.21 does not properly reset the metadata of a file during replacement of the file in a package upgrade, which might allow local users to gain…EPSS 0.41%7.1CVE-2014-3127Debian dpkg path traversal vulnerabilitydpkg 1.15.9 on Debian squeeze introduces support for the "C-style encoded filenames" feature without recognizing that the squeeze patch program lacks…EPSS 2.1%6.8CVE-2014-8625Debian dpkg vulnerabilityMultiple format string vulnerabilities in the parse_error_msg function in parsehelp.c in dpkg before 1.17.22 allow remote attackers to cause a denial…EPSS 3.3%6.8CVE-2011-0402Debian dpkg link following vulnerabilitydpkg-source in dpkg before 1.14.31 and 1.15.x allows user-assisted remote attackers to modify arbitrary files via a symlink attack on unspecified fil…EPSS 2.9%

Source: NIST National Vulnerability Database (record CVE-2017-8283), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.