drucken bookmarks versenden konfigurieren admin pdf Sicherheit: Zwei Probleme in ZZIPlib
Name: |
Zwei Probleme in ZZIPlib |
|
ID: |
USN-6298-1 |
|
Distribution: |
Ubuntu |
|
Plattformen: |
Ubuntu 20.04 LTS, Ubuntu 16.04 LTS (Available with Ubuntu Pro), Ubuntu 18.04 LTS (Available with Ubuntu Pro) |
|
Datum: |
Do, 17. August 2023, 22:33 |
|
Referenzen: |
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-18442
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-7727 |
|
Applikationen: |
ZZIPlib |
|
Originalnachricht |
This is an OpenPGP/MIME signed message (RFC 4880 and 3156) --===============9089842837421598390== Content-Language: en-US Content-Type: multipart/signed; micalg=pgp-sha256; protocol="application/pgp-signature"; boundary="------------F4oyhnsZa1Z9Uyn5MvBrvgYa"
This is an OpenPGP/MIME signed message (RFC 4880 and 3156) --------------F4oyhnsZa1Z9Uyn5MvBrvgYa Content-Type: multipart/mixed; boundary="------------ssO0xDMKH80VK2PeC7Dc41un"; protected-headers="v1" From: Amir Naseredini <amir.naseredini@canonical.com> To: ubuntu-security-announce@lists.ubuntu.com Message-ID: <5c0e59fb-1006-3aa3-26f2-e6cb868ce5fb@canonical.com> Subject: [USN-6298-1] ZZIPlib vulnerabilities
--------------ssO0xDMKH80VK2PeC7Dc41un Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: base64
========================================================================== Ubuntu Security Notice USN-6298-1 August 17, 2023
zziplib vulnerabilities ==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 20.04 LTS - Ubuntu 18.04 LTS (Available with Ubuntu Pro) - Ubuntu 16.04 LTS (Available with Ubuntu Pro)
Summary:
Several security issues were fixed in ZZIPlib.
Software Description: - zziplib: The ZZIPlib provides read access on ZIP-archives and unpacked data
Details:
Liu Zhu discovered that ZZIPlib incorrectly handled certain inputs. If a user or an automated system were tricked into opening a specially crafted input file, a remote attacker could possibly use this issue to cause a denial of service. (CVE-2018-7727)
YiMing Liu discovered that ZZIPlib incorrectly handled certain inputs. If a user or an automated system were tricked into opening a specially crafted input file, a remote attacker could possibly use this issue to cause a denial of service. (CVE-2020-18442)
Update instructions:
The problem can be corrected by updating your system to the following package versions:
Ubuntu 20.04 LTS: libzzip-0-13 0.13.62-3.2ubuntu1.1 libzzip-dev 0.13.62-3.2ubuntu1.1 zziplib-bin 0.13.62-3.2ubuntu1.1
Ubuntu 18.04 LTS (Available with Ubuntu Pro): libzzip-0-13 0.13.62-3.1ubuntu0.18.04.1+esm1 libzzip-dev 0.13.62-3.1ubuntu0.18.04.1+esm1 zziplib-bin 0.13.62-3.1ubuntu0.18.04.1+esm1
Ubuntu 16.04 LTS (Available with Ubuntu Pro): libzzip-0-13 0.13.62-3ubuntu0.16.04.2+esm1 libzzip-dev 0.13.62-3ubuntu0.16.04.2+esm1 zziplib-bin 0.13.62-3ubuntu0.16.04.2+esm1
In general, a standard system update will make all the necessary changes.
References: https://ubuntu.com/security/notices/USN-6298-1 CVE-2018-7727, CVE-2020-18442
Package Information: https://launchpad.net/ubuntu/+source/zziplib/0.13.62-3.2ubuntu1.1 --------------ssO0xDMKH80VK2PeC7Dc41un--
--------------F4oyhnsZa1Z9Uyn5MvBrvgYa Content-Type: application/pgp-signature; name="OpenPGP_signature.asc" Content-Description: OpenPGP digital signature Content-Disposition: attachment; filename="OpenPGP_signature"
-----BEGIN PGP SIGNATURE-----
wsD5BAABCAAjFiEELRdhz3KY7FGicMD8Vjg+NdFTuLIFAmTeT/kFAwAAAAAACgkQVjg+NdFTuLL0 /AwA2vye3pkPIFdNBN+ga+/uWW7L02Z5D1uVExn7SdujoDSV8i/HXkQm/g3sMT1YiyYQ1rkvs2nw WF0z8N27HoiwQ66gz7A/qoYyFpfyZiRCMeADCgm0vgacTQ3CBO9CaNEVnc1mZaeBeJl0s3PUG3hr Is48XwUQBnn8BT5kHdT0IFWQtgfRYOQ0nMgl+2zIeuG291LrACTOqLs237xX02KRK7E+EmKkQX/W z1gfWAXvLeCK+Rz8jakS5dih5JxwytX6ZMyZ8Ubfih1ICUCyJ7eM7lP5pWOqvoau9nxUl+WSvkvF 8ce4kU4tNZih3vYFW/FROoj52U/SOyehscuH7QW50S54lHqgGtDDDLQUFnkgp4mtXUio55ZDowBQ VSBNfsiAnQt5yu85oyZXWXKJclF30YRBhOV8HUCeN9Zu/t58m3wRcaUCD8KhDveIjIotWS7Z3ICI hbEKpVRupQzpIAawqcQFcDqcL+kaacTRHmTSO5RnGQK27vdfJgFJz8Qn4Yjv =6/PK -----END PGP SIGNATURE-----
--------------F4oyhnsZa1Z9Uyn5MvBrvgYa--
--===============9089842837421598390== Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: base64 Content-Disposition: inline
Cg==
--===============9089842837421598390==--
|
|
|
|