Login
Newsletter
Werbung

Sicherheit: Zwei Probleme in ZZIPlib
Aktuelle Meldungen Distributionen
Name: Zwei Probleme in ZZIPlib
ID: USN-6298-1
Distribution: Ubuntu
Plattformen: Ubuntu 20.04 LTS, Ubuntu 16.04 LTS (Available with Ubuntu Pro), Ubuntu 18.04 LTS (Available with Ubuntu Pro)
Datum: Do, 17. August 2023, 22:33
Referenzen: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-18442
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-7727
Applikationen: ZZIPlib

Originalnachricht

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--===============9089842837421598390==
Content-Language: en-US
Content-Type: multipart/signed; micalg=pgp-sha256;
protocol="application/pgp-signature";
boundary="------------F4oyhnsZa1Z9Uyn5MvBrvgYa"

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--------------F4oyhnsZa1Z9Uyn5MvBrvgYa
Content-Type: multipart/mixed;
boundary="------------ssO0xDMKH80VK2PeC7Dc41un";
protected-headers="v1"
From: Amir Naseredini <amir.naseredini@canonical.com>
To: ubuntu-security-announce@lists.ubuntu.com
Message-ID: <5c0e59fb-1006-3aa3-26f2-e6cb868ce5fb@canonical.com>
Subject: [USN-6298-1] ZZIPlib vulnerabilities

--------------ssO0xDMKH80VK2PeC7Dc41un
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: base64

==========================================================================
Ubuntu Security Notice USN-6298-1
August 17, 2023

zziplib vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS (Available with Ubuntu Pro)
- Ubuntu 16.04 LTS (Available with Ubuntu Pro)

Summary:

Several security issues were fixed in ZZIPlib.

Software Description:
- zziplib: The ZZIPlib provides read access on ZIP-archives and unpacked data

Details:

Liu Zhu discovered that ZZIPlib incorrectly handled certain inputs. If a
user or an automated system were tricked into opening a specially crafted
input file, a remote attacker could possibly use this issue to cause a
denial of service. (CVE-2018-7727)

YiMing Liu discovered that ZZIPlib incorrectly handled certain inputs. If a
user or an automated system were tricked into opening a specially crafted
input file, a remote attacker could possibly use this issue to cause a
denial of service. (CVE-2020-18442)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 20.04 LTS:
libzzip-0-13 0.13.62-3.2ubuntu1.1
libzzip-dev 0.13.62-3.2ubuntu1.1
zziplib-bin 0.13.62-3.2ubuntu1.1

Ubuntu 18.04 LTS (Available with Ubuntu Pro):
libzzip-0-13 0.13.62-3.1ubuntu0.18.04.1+esm1
libzzip-dev 0.13.62-3.1ubuntu0.18.04.1+esm1
zziplib-bin 0.13.62-3.1ubuntu0.18.04.1+esm1

Ubuntu 16.04 LTS (Available with Ubuntu Pro):
libzzip-0-13 0.13.62-3ubuntu0.16.04.2+esm1
libzzip-dev 0.13.62-3ubuntu0.16.04.2+esm1
zziplib-bin 0.13.62-3ubuntu0.16.04.2+esm1

In general, a standard system update will make all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-6298-1
CVE-2018-7727, CVE-2020-18442

Package Information:
https://launchpad.net/ubuntu/+source/zziplib/0.13.62-3.2ubuntu1.1
--------------ssO0xDMKH80VK2PeC7Dc41un--

--------------F4oyhnsZa1Z9Uyn5MvBrvgYa
Content-Type: application/pgp-signature; name="OpenPGP_signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="OpenPGP_signature"

-----BEGIN PGP SIGNATURE-----

wsD5BAABCAAjFiEELRdhz3KY7FGicMD8Vjg+NdFTuLIFAmTeT/kFAwAAAAAACgkQVjg+NdFTuLL0
/AwA2vye3pkPIFdNBN+ga+/uWW7L02Z5D1uVExn7SdujoDSV8i/HXkQm/g3sMT1YiyYQ1rkvs2nw
WF0z8N27HoiwQ66gz7A/qoYyFpfyZiRCMeADCgm0vgacTQ3CBO9CaNEVnc1mZaeBeJl0s3PUG3hr
Is48XwUQBnn8BT5kHdT0IFWQtgfRYOQ0nMgl+2zIeuG291LrACTOqLs237xX02KRK7E+EmKkQX/W
z1gfWAXvLeCK+Rz8jakS5dih5JxwytX6ZMyZ8Ubfih1ICUCyJ7eM7lP5pWOqvoau9nxUl+WSvkvF
8ce4kU4tNZih3vYFW/FROoj52U/SOyehscuH7QW50S54lHqgGtDDDLQUFnkgp4mtXUio55ZDowBQ
VSBNfsiAnQt5yu85oyZXWXKJclF30YRBhOV8HUCeN9Zu/t58m3wRcaUCD8KhDveIjIotWS7Z3ICI
hbEKpVRupQzpIAawqcQFcDqcL+kaacTRHmTSO5RnGQK27vdfJgFJz8Qn4Yjv
=6/PK
-----END PGP SIGNATURE-----

--------------F4oyhnsZa1Z9Uyn5MvBrvgYa--


--===============9089842837421598390==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline

Cg==

--===============9089842837421598390==--
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung