Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Ubuntu 16.04 ESM USN-5378-3 Critical: XZ Utils Overwrite Risk

Ubuntu Large Esm H500
XZ Utils could be made to overwrite arbitrary files.
=========================================================================Ubuntu Security Notice USN-5378-3
April 13, 2022

xz-utils vulnerability
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 16.04 ESM
- Ubuntu 14.04 ESM

Summary:

XZ Utils could be made to overwrite arbitrary files.

Software Description:
- xz-utils: XZ-format compression utilities

Details:

USN-5378-2 fixed a vulnerability in XZ Utils. This update provides
the corresponding update for Ubuntu 14.04 ESM and 16.04 ESM.

Original advisory details:

 Cleemy Desu Wayo discovered that Gzip incorrectly handled certain
 filenames. If a user or automated system were tricked into performing zgrep
 operations with specially crafted filenames, a remote attacker could
 overwrite arbitrary files.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 16.04 ESM:
  xz-utils                        5.1.1alpha+20120614-2ubuntu2.16.04.1+esm1

Ubuntu 14.04 ESM:
  xz-utils                        5.1.1alpha+20120614-2ubuntu2.14.04.1+esm1

In general, a standard system update will make all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-5378-3
  https://ubuntu.com/security/notices/USN-5378-1
  CVE-2022-1271

Ubuntu 16.04 ESM USN-5378-3 Critical: XZ Utils Overwrite Risk

ubuntu
Calendar Grey April 13, 2022
Dist Ubuntu Esm H88
Explore the Ubuntu Security Advisory USN-5378-3, which tackles the XZ Utils flaw enabling unrestricted file overwriting.
XZ Utils could be made to overwrite arbitrary files.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 ESM: xz-utils 5.1.1alpha+20120614-2ubuntu2.16.04.1+esm1 Ubuntu 14.04 ESM: xz-utils 5.1.1alpha+20120614-2ubuntu2.14.04.1+esm1 In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-5378-3

https://ubuntu.com/security/notices/USN-5378-1

CVE-2022-1271

Severity
critical
Lowest
Low
Medium
High
Critical

April 13, 2022

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here