Alerts This Week
Warning Icon 1 609
Alerts This Week
Warning Icon 1 609

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
172

Ubuntu 22.04 LTS USN-7030-1 Moderate: py7zr Path Traversal Risk

py7zr could be made to create arbitrary files when extracting the contents of a specially crafted 7z archive.. ========================================================================== Ubuntu Security Notice USN-7030-1 September 24, 2024 py7zr vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 22.04 LTS Summary: py7zr could be made to create arbitrary files when extracting the contents of a specially crafted 7z archive. Software Description: - py7zr: Pure Python 7-zip library Details: It was discovered that py7zr was vulnerable to path traversal attacks. If a user or automated system were tricked into extracting a specially crafted 7z archive, an attacker could possibly use this issue to write arbitrary files outside the target directory on the host. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 22.04 LTS python3-py7zr 0.11.3+dfsg-4ubuntu0.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7030-1 CVE-2022-44900 Package Information: https://launchpad.net/ubuntu/+source/py7zr/0.11.3+dfsg-4ubuntu0.1 . To bolster your Ubuntu system's security, tackle the py7zr vulnerability that might permit unauthorized file creation. Run the following commands to update and resolve this issue. py7zr, Ubuntu Security, Path Traversal, File Extraction. . LinuxSecurity.com Team

Calendar 2 Sep 24, 2024 Ubuntu
87

Debian Bullseye: DSA-5652-1 Critical Issue in Py7zr Directory Traversal

A directory traversal vulnerability was discovered in py7zr, a library and command-line utility to process 7zip archives. For the oldstable distribution (bullseye), this problem has been fixed . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5652-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff April 02, 2024 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : py7zr CVE ID : CVE-2022-44900 A directory traversal vulnerability was discovered in py7zr, a library and command-line utility to process 7zip archives. For the oldstable distribution (bullseye), this problem has been fixed in version 0.11.3+dfsg-1+deb11u1. We recommend that you upgrade your py7zr packages. For the detailed security status of py7zr please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/py7zr Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Update the py7zr package on Debian Bullseye to fix the directory traversal vulnerability cited in advisory DSA-5652-1 for system integrity and security. Debian Security, Py7zr Update, Directory Traversal Fix. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Apr 02, 2024 Critical Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here