=========================================================================Ubuntu Security Notice USN-5378-3
April 13, 2022

xz-utils vulnerability
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 16.04 ESM
- Ubuntu 14.04 ESM

Summary:

XZ Utils could be made to overwrite arbitrary files.

Software Description:
- xz-utils: XZ-format compression utilities

Details:

USN-5378-2 fixed a vulnerability in XZ Utils. This update provides
the corresponding update for Ubuntu 14.04 ESM and 16.04 ESM.

Original advisory details:

 Cleemy Desu Wayo discovered that Gzip incorrectly handled certain
 filenames. If a user or automated system were tricked into performing zgrep
 operations with specially crafted filenames, a remote attacker could
 overwrite arbitrary files.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 16.04 ESM:
  xz-utils                        5.1.1alpha+20120614-2ubuntu2.16.04.1+esm1

Ubuntu 14.04 ESM:
  xz-utils                        5.1.1alpha+20120614-2ubuntu2.14.04.1+esm1

In general, a standard system update will make all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-5378-3
  https://ubuntu.com/security/notices/USN-5378-1
  CVE-2022-1271

Ubuntu 5378-3: XZ Utils vulnerability

April 13, 2022
XZ Utils could be made to overwrite arbitrary files.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 ESM: xz-utils 5.1.1alpha+20120614-2ubuntu2.16.04.1+esm1 Ubuntu 14.04 ESM: xz-utils 5.1.1alpha+20120614-2ubuntu2.14.04.1+esm1 In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-5378-3

https://ubuntu.com/security/notices/USN-5378-1

CVE-2022-1271

Severity
April 13, 2022

Package Information

Related News