Alerts This Week
Warning Icon 1 631
Alerts This Week
Warning Icon 1 631

Ubuntu 20.04 LTS USN-6220-1 High: libxml2 Memory Corruption Vulnerability

Ubuntu Large Esm H500
lib3mf could be made to execute arbitrary code if it opens a specially crafted 3MF file.
=========================================================================Ubuntu Security Notice USN-6216-1
July 11, 2023

lib3mf vulnerability
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 20.04 LTS

Summary:

lib3mf could be made to execute arbitrary code if it opens a specially 
crafted 3MF file.

Software Description:
- lib3mf: Lib3MF is a C++ implementation of the 3D Manufacturing Format

Details:

It was discovered that lib3mf did not properly manage memory under
certain circumstances. If a user were tricked into opening a specially
crafted 3MF file, a local attacker could possibly use this issue to
cause applications using lib3mf to crash, resulting in a denial of
service, or possibly execute arbitrary code.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 20.04 LTS:
   lib3mf-dev                      1.8.1+ds-3ubuntu0.2
   lib3mf1                         1.8.1+ds-3ubuntu0.2

In general, a standard system update will make all the necessary changes.

References:
   https://ubuntu.com/security/notices/USN-6216-1
   CVE-2021-21772

Package Information:
   https://launchpad.net/ubuntu/+source/lib3mf/1.8.1+ds-3ubuntu0.2

Ubuntu 20.04 LTS USN-6220-1 High: libxml2 Memory Corruption Vulnerability

ubuntu
Calendar Grey July 12, 2023
Dist Ubuntu Esm H88
Vulnerability identified in lib3mf on Ubuntu 20.04, allowing arbitrary code execution through specifically crafted 3MF files when accessed by various applications.
lib3mf could be made to execute arbitrary code if it opens a specially crafted 3MF file.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS:   lib3mf-dev                      1.8.1+ds-3ubuntu0.2   lib3mf1                         1.8.1+ds-3ubuntu0.2 In general, a standard system update will make all the necessary changes.

References

  https://ubuntu.com/security/notices/USN-6216-1

  CVE-2021-21772

July 11, 2023

Package Information

  https://launchpad.net/ubuntu/+source/lib3mf/1.8.1+ds-3ubuntu0.2

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here