Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
py7zr could be made to create arbitrary files when extracting the contents
of a specially crafted 7z archive.
Software Description:
- py7zr: Pure Python 7-zip library
Details:
It was discovered that py7zr was vulnerable to path traversal attacks.
If a user or automated system were tricked into extracting a specially
crafted 7z archive, an attacker could possibly use this issue to write
arbitrary files outside the target directory on the host.
The problem can be corrected by updating your system to the following package versions: Ubuntu 22.04 LTS python3-py7zr 0.11.3+dfsg-4ubuntu0.1 In general, a standard system update will make all the necessary changes.
https://ubuntu.com/security/notices/USN-7030-1
CVE-2022-44900
Get the latest Linux and open source security news straight to your inbox.