Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Fedora 35: FEDORA-2022-0ff8149aad Critical: qpress Directory Traversal

fedora
Calendar Grey December 4, 2022
Dist Fedora Esm H88
Explore the Fedora advisory for qpress addressing CVE-2022-45866 and crucial security updates.
Security fix for CVE-2022-45866

Summary

qpress is a portable file archiver using QuickLZ and designed to utilize fast

storage systems to their max. It's often faster than file copy because the

destination is smaller than the source.

Security fix for CVE-2022-45866

* Fri Nov 25 2022 Davide Cavalca 20220819-1

- Switch to new upstream and update to 20220819 (Fixes: RHBZ#2147535,

RHBZ#2147537)

* Fri Jul 22 2022 Fedora Release Engineering 11-2

- Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild

[ 1 ] Bug #2147535 - CVE-2022-45866 qpress: directory traversal via ../ in a .qp file

https://bugzilla.redhat.com/show_bug.cgi?id=2147535

su -c 'dnf upgrade --advisory FEDORA-2022-0ff8149aad' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Do not reply to spam, report it:

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 35
Version: 20220819
Release: 1.fc35
URL: Summary : A portable file archiver using QuickLZ

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here