Login
Newsletter
Werbung

Sicherheit: Ausführen beliebiger Kommandos in Zstandard
Aktuelle Meldungen Distributionen
Name: Ausführen beliebiger Kommandos in Zstandard
ID: USN-4108-1
Distribution: Ubuntu
Plattformen: Ubuntu 18.04 LTS
Datum: Mi, 21. August 2019, 20:01
Referenzen: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11922
Applikationen: Zstandard

Originalnachricht


--===============0432813518516296293==
Content-Type: multipart/signed; micalg=pgp-sha1;
protocol="application/pgp-signature";
boundary="45Z9DzgjV8m4Oswq"
Content-Disposition: inline


--45Z9DzgjV8m4Oswq
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline

==========================================================================
Ubuntu Security Notice USN-4108-1
August 21, 2019

libzstd vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 18.04 LTS

Summary:

Zstandard could be made to execute arbitrary code if it received
specially crafted input.

Software Description:
- libzstd: fast lossless compression algorithm -- development files

Details:

It was discovered that Zstandard incorrectly handled certain inputs.
An attacker could possibly use this issue to execute arbitrary code.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 18.04 LTS:
libzstd1 1.3.3+dfsg-2ubuntu1.1
zstd 1.3.3+dfsg-2ubuntu1.1

In general, a standard system update will make all the necessary changes.

References:
https://usn.ubuntu.com/4108-1
CVE-2019-11922

Package Information:
https://launchpad.net/ubuntu/+source/libzstd/1.3.3+dfsg-2ubuntu1.1

--45Z9DzgjV8m4Oswq
Content-Type: application/pgp-signature; name="signature.asc"

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIcBAEBAgAGBQJdXWAzAAoJEEW851uECx9p4DcP/iYpqWXxA9J4qSmPiUoQaHld
oypI7nM1vVmjQ80Tz477EvwKLN9ArT+7R2uTut6/n+VUyV/SNp/3Q8Owo9+//kYA
owybql0OlfrGEEEhIZXVr0l3O9/Y/lWCzEI6ymaft1VdGLEPY/1TyNiHFoQq9FBt
S5MfeL1Q8ComSCTZJktU6wmcIwHJUQcMGpU1TsfjbWS3+xAFwsLVm/loAqCDoxmH
S9gt0jhQtbrfAyLqKLRKtJKjcR43zZ+hhQ6TP7v7uhg9eMa9zucqv2TqFTtgWZGj
XVCf6EkxnV964ODx3ETBlFytzI9SHICiwNVONZZiO6FRWGbYi4S64ZF6x1yNX90a
Oz7YdvKLd5LhlvWxHsq2gIkkClFcza3koaOcoFKdKdpWtNckUguSr2uXK5qpepML
Xo/FZYo3zB4AOQmH6AgBbjp2E2xPTwMjmSlX7OhJ5CFR2NmicW9T0XiK2IEQW7lY
KjcE9P8ZLJna/E6zOMBjY4U47Q6oFc/yGigAoz0P4oeP/jUxNEZHc8G4CYkTLvYh
nV/KZiEsVXJRqczQ8O42H5ZPFxqaPASJz9/TPJaxGGkRPWKDKVli0PjRtp7M9tLx
t+HAtOWn88lQzG/NgRkUKV/JoZfQuOxtmk93sYZItbbNYl713Vk8JTFO7BLnRyqd
xZ1XC7BFOac7h7xtmsLY
=Uuhu
-----END PGP SIGNATURE-----

--45Z9DzgjV8m4Oswq--


--===============0432813518516296293==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline

--
ubuntu-security-announce mailing list
ubuntu-security-announce@lists.ubuntu.com
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung