Alerts This Week
Warning Icon 1 631
Alerts This Week
Warning Icon 1 631

SUSE: 2018:3220-1 Moderate: Fix for zziplib Path Traversal Issue

suse
Calendar Grey October 18, 2018
Dist Suse Esm H88
Recent patch for zziplib resolves a path traversal vulnerability rated as moderate in severity. It is advisable to upgrade using the suggested installation procedures immediately.
An update that fixes one vulnerability is now available

Summary

This update for zziplib fixes the following issues: - CVE-2018-17828: Remove any "../" components from pathnames of extracted files to avoid path traversal during unpacking. (bsc#1110687) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Basesystem 15: zypper in -t patch SUSE-SLE-Module-Basesystem-15-2018-2302=1 Package List: - SUSE Linux Enterprise Module for Basesystem 15 (aarch64 ppc64le s390x x86_64): libzzip-0-13-0.13.69-3.3.1 libzzip-0-13-debuginfo-0.13.69-3.3.1 zziplib-debugsource-0.13.69-3.3.1 zziplib-devel-0.13.69-3.3.1 zziplib-devel-debuginfo-0.13.69-3.3.1

References

#1110687

Cross- CVE-2018-17828

Affected Products:

SUSE Linux Enterprise Module for Basesystem 15

https://www.suse.com/security/cve/CVE-2018-17828.html

https://bugzilla.suse.com/1110687

Announcement ID: SUSE-SU-2018:3220-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here