Alerts This Week
Warning Icon 1 923
Alerts This Week
Warning Icon 1 923

Mageia 9: MGASA-2024-0019 Moderate: Zlib Remote File Access Issue

mageia
Calendar Grey January 30, 2024
Dist Mageia Esm H88
Revised zlib libraries rectify a directory traversal vulnerability that permits remote file retrieval through specially designed ZIP files.
Updated zlib packages fix a security vulnerability: Directory traversal vulnerability in the do_extract_currentfile function in miniunz.c in miniunzip in minizip before 1.1-5 migh...

Summary

Updated zlib packages fix a security vulnerability:
Directory traversal vulnerability in the do_extract_currentfile function in miniunz.c in miniunzip in minizip before 1.1-5 might allow remote attackers to write to arbitrary files via a crafted entry in a ZIP archive.

References

- https://bugs.mageia.org/show_bug.cgi?id=32785

- https://www.openwall.com/lists/oss-security/2024/01/24/10

- https://www.cve.org/CVERecord?id=CVE-2014-9485

Resolution

SRPMS

- 9/core/zlib-1.2.13-1.2.mga9

Publication date: 30 Jan 2024
URL: https://advisories.mageia.org/MGASA-2024-0019.html
Type: security
CVE: CVE-2014-9485

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here