Security
Headlines
HeadlinesLatestCVEs

Headline

Ubuntu Security Notice USN-5840-1

Ubuntu Security Notice 5840-1 - It was discovered that Long Range ZIP incorrectly handled pointers. If a user or an automated system were tricked into opening a certain specially crafted ZIP file, an attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 14.04 ESM, Ubuntu 16.04 ESM, Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS. It was discovered that Long Range ZIP incorrectly handled pointers. If a user or an automated system were tricked into opening a certain specially crafted ZIP file, an attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS.

Packet Storm
#vulnerability#ubuntu#dos#git
==========================================================================Ubuntu Security Notice USN-5840-1February 02, 2023lrzip vulnerabilities==========================================================================A security issue affects these releases of Ubuntu and its derivatives:- Ubuntu 22.10- Ubuntu 22.04 LTS- Ubuntu 20.04 LTS- Ubuntu 18.04 LTS- Ubuntu 16.04 ESM- Ubuntu 14.04 ESMSummary:Several security issues were fixed in Long Range ZIP.Software Description:- lrzip: compression program with a very high compression ratioDetails:It was discovered that Long Range ZIP incorrectly handled pointers. Ifa user or an automated system were tricked into opening a certainspecially crafted ZIP file, an attacker could possibly use this issueto cause a denial of service. This issue only affected Ubuntu 14.04 ESM,Ubuntu 16.04 ESM, Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS. (CVE-2020-25467)It was discovered that Long Range ZIP incorrectly handled pointers. Ifa user or an automated system were tricked into opening a certainspecially crafted ZIP file, an attacker could possibly use this issueto cause a denial of service. This issue only affected Ubuntu 18.04 LTSand Ubuntu 20.04 LTS. (CVE-2021-27345, CVE-2021-27347)It was discovered that Long Range ZIP incorrectly handled pointers. Ifa user or an automated system were tricked into opening a certainspecially crafted ZIP file, an attacker could possibly use this issueto cause a denial of service. This issue only affected Ubuntu 16.04 ESM,Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS. (CVE-2022-26291)It was discovered that Long Range ZIP incorrectly handled memory allocation,which could lead to a heap memory corruption. An attacker could possibly usethis issue to cause denial of service. This issue affected Ubuntu 14.04 ESM,Ubuntu 16.04 ESM, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, andUbuntu 22.10. (CVE-2022-28044)Update instructions:The problem can be corrected by updating your system to the followingpackage versions:Ubuntu 22.10:   lrzip                           0.651-2ubuntu0.22.10.1Ubuntu 22.04 LTS:   lrzip                           0.651-2ubuntu0.22.04.1Ubuntu 20.04 LTS:   lrzip 0.631+git180528-1+deb10u1build0.20.04.1Ubuntu 18.04 LTS:   lrzip                           0.631-1+deb9u3build0.18.04.1Ubuntu 16.04 ESM:   lrzip                           0.621-1ubuntu0.1~esm2Ubuntu 14.04 ESM:   lrzip                           0.616-1ubuntu0.1~esm2In general, a standard system update will make all the necessary changes.References:   https://ubuntu.com/security/notices/USN-5840-1   CVE-2018-5786, CVE-2020-25467, CVE-2021-27345, CVE-2021-27347,   CVE-2022-26291, CVE-2022-28044Package Information:https://launchpad.net/ubuntu/+source/lrzip/0.651-2ubuntu0.22.10.1https://launchpad.net/ubuntu/+source/lrzip/0.651-2ubuntu0.22.04.1https://launchpad.net/ubuntu/+source/lrzip/0.631+git180528-1+deb10u1build0.20.04.1https://launchpad.net/ubuntu/+source/lrzip/0.631-1+deb9u3build0.18.04.1

Related news

CVE-2022-28044: Fix control->suffix being deallocated as heap memory as reported by P… · ckolivas/lrzip@5faf80c

Irzip v0.640 was discovered to contain a heap memory corruption via the component lrzip.c:initialise_control.

CVE-2022-26291: Multiple concurrency UAF bug between `zpaq_decompress_buf()` and `clear_rulist()` function · Issue #206 · ckolivas/lrzip

lrzip v0.641 was discovered to contain a multiple concurrency use-after-free between the functions zpaq_decompress_buf() and clear_rulist(). This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted Irz file.

CVE-2018-5786: Infinite Loop Vulnerability in get_fileinfo (src/lrzip.c) · Issue #91 · ckolivas/lrzip

In Long Range Zip (aka lrzip) 0.631, there is an infinite loop and application hang in the get_fileinfo function (lrzip.c). Remote attackers could leverage this vulnerability to cause a denial of service via a crafted lrz file.

Packet Storm: Latest News

Pyload Remote Code Execution