Zstandard could be made to expose sensitive information. =========================================================================Ubuntu Security Notice USN-5720-1 November 09, 2022 libzstd vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.04 ESM Summary: Zstandard could be made to expose sensitive information Software Description: - libzstd: fast lossless compression algorithm Details: It was discovered that Zstandard was not properly managing file permissions when generating output files. A local attacker could possibly use this issue to cause a race condition and gain unauthorized access to sensitive data. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 ESM: libzstd1 1.3.1+dfsg-1~ubuntu0.16.04.1+esm3 zstd 1.3.1+dfsg-1~ubuntu0.16.04.1+esm3 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-5720-1 CVE-2021-24031, CVE-2021-24032 . Ubuntu Security Notice USN-5720-2 concerns flaws in libzstd that could allow for the potential leakage of confidential information via localized exploits.. libzstd security, Ubuntu issue, information exposure risk, update instructions. . LinuxSecurity.com Team
Zstandard could be made to execute arbitrary code if it received specially crafted input.. =========================================================================Ubuntu Security Notice USN-5593-1 September 01, 2022 libzstd vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.04 ESM Summary: Zstandard could be made to execute arbitrary code if it received specially crafted input. Software Description: - libzstd: fast lossless compression algorithm Details: It was discovered that Zstandard incorrectly handled certain inputs. An attacker could possibly use this issue to execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 ESM: libzstd1 1.3.1+dfsg-1~ubuntu0.16.04.1+esm2 zstd 1.3.1+dfsg-1~ubuntu0.16.04.1+esm2 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-5593-1 CVE-2019-11922 . A vulnerability in Zstandard may enable arbitrary code execution with specially formed inputs, affecting various Ubuntu versions. Refer to the provided update guidelines.. libzstd vulnerabilities, arbitrary code execution, Ubuntu security advisory. . LinuxSecurity.com Team
libzstd could be made to expose sensitive information.. =========================================================================Ubuntu Security Notice USN-4760-1 March 08, 2021 libzstd vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.10 - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: libzstd could be made to expose sensitive information. Software Description: - libzstd: fast lossless compression algorithm Details: It was discovered that libzstd incorrectly handled file permissions. A local attacker could possibly use this issue to access certain files, contrary to expectations. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.10: libzstd1 1.4.5+dfsg-4ubuntu0.1 zstd 1.4.5+dfsg-4ubuntu0.1 Ubuntu 20.04 LTS: libzstd1 1.4.4+dfsg-3ubuntu0.1 zstd 1.4.4+dfsg-3ubuntu0.1 Ubuntu 18.04 LTS: libzstd1 1.3.3+dfsg-2ubuntu1.2 zstd 1.3.3+dfsg-2ubuntu1.2 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-4760-1 CVE-2021-24031, CVE-2021-24032 Package Information: https://launchpad.net/ubuntu/+source/libzstd/1.4.5+dfsg-4ubuntu0.1 https://launchpad.net/ubuntu/+source/libzstd/1.4.4+dfsg-3ubuntu0.1 https://launchpad.net/ubuntu/+source/libzstd/1.3.3+dfsg-2ubuntu1.2 . The Ubuntu security notice USN-4760-1 draws attention to vulnerabilities in libzstd that may lead to the exposure of confidential information across various versions.. libzstd exposures, Ubuntu updates, security threats. . Severity: Critical. LinuxSecurity.com Team
It was discovered that zstd, a compression utility, was vulnerable to a race condition: it temporarily exposed, during a very short timeframe, a world-readable version of its input even if the original file had restrictive permissions. . - ----------------------------------------------------------------------- Debian LTS Advisory DLA-2573-1
It was discovered that zstd, a compression utility, was vulnerable to a race condition: it temporarily exposed, during a very short timeframe, a world-readable version of its input even if the original file had restrictive permissions. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-4859-1
It was discovered that zstd, a compression utility, temporarily exposed a world-readable version of its input even if the original file had restrictive permissions. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-4850-1
Zstandard could be made to execute arbitrary code if it received specially crafted input.. =========================================================================Ubuntu Security Notice USN-4108-1 August 21, 2019 libzstd vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 18.04 LTS Summary: Zstandard could be made to execute arbitrary code if it received specially crafted input. Software Description: - libzstd: fast lossless compression algorithm -- development files Details: It was discovered that Zstandard incorrectly handled certain inputs. An attacker could possibly use this issue to execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 18.04 LTS: libzstd1 1.3.3+dfsg-2ubuntu1.1 zstd 1.3.3+dfsg-2ubuntu1.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-4108-1 CVE-2019-11922 Package Information: https://launchpad.net/ubuntu/+source/libzstd/1.3.3+dfsg-2ubuntu1.1 . A significant alert regarding a vulnerability in Ubuntu's libzstd, which could enable remote attackers to execute arbitrary code via intricately constructed inputs.. Ubuntu Security Notice, libzstd update, critical vulnerability, arbitrary code execution. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.