Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 471
Alerts This Week
Warning Icon 1 471

Ubuntu 16.04 LTS: USN-4500-1 High: bsdiff Crash and Execute Threat

ubuntu
Calendar Grey September 15, 2020
Scroller Ubuntu
The latest Ubuntu Security Notation USN-4501-1 addresses critical flaws in bsdiff for Ubuntu 18.04, posing threats of system instability and unauthorized code execution.
bsdiff could be made to crash or run programs as your login if it opened a specially crafted file.

Summary

bsdiff could be made to crash or run programs as your login if it

opened a specially crafted file.

Software Description:

- bsdiff: generate/apply a patch between two binary files

Details:

It was discovered that bsdiff mishandled certain input. If a user were tricked

into opening a malicious file, an attacker could cause bsdiff to crash or

potentially execute arbitrary code.

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 16.04 LTS:
  bsdiff                          4.3-15+deb8u1build0.16.04.1

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-4500-1

CVE-2014-9862

Severity
important
Lowest
Low
Medium
High
Critical

September 15, 2020

Package Information

--
ubuntu-security-announce mailing list
ubuntu-security-announce@lists.ubuntu.com
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.