zutils version prior to version 1.8-pre2 contains a buffer overflow vulnerability in zcat which happened with some input files when the '-v, --show-nonprinting' option was . Package : zutils Version : 1.3-4+deb8u1 CVE ID : CVE-2018-1000637 Debian Bug : 902936 zutils version prior to version 1.8-pre2 contains a buffer overflow vulnerability in zcat which happened with some input files when the '-v, --show-nonprinting' option was used (or indirectly enabled). This can result in potential denial of service or arbitrary code execution. This attack appear is exploitable via the victim openning a crafted compressed file and has been fixed in 1.8-pre2. For Debian 8 "Jessie", this problem has been fixed in version 1.3-4+deb8u1. We recommend that you upgrade your zutils packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS Regards, Daniel . Enhance zutils as a result of an urgent buffer overflow vulnerability discovered in Debian 8, which has the potential to cause denial of service (DoS) or unauthorized code execution.. Debian LTS,zutils update,buffer overflow,code execution,security patch. . Severity: Critical. LinuxSecurity.com Team
An update that fixes one vulnerability is now available.. openSUSE Security Update: Security update for zutils ______________________________________________________________________________ Announcement ID: openSUSE-SU-2018:2591-1 Rating: moderate References: #1103878 Cross-References: CVE-2018-1000637 Affected Products: openSUSE Leap 42.3 openSUSE Leap 15.0 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for zutils to version 1.7 fixes one security issue: - CVE-2018-1000637: buffer overrun in zcat utility (boo#1103878) Please note that the zutils zcat utility is distinct from the default gzip zcat utility. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 42.3: zypper in -t patch openSUSE-2018-951=1 - openSUSE Leap 15.0: zypper in -t patch openSUSE-2018-951=1 Package List: - openSUSE Leap 42.3 (x86_64): zutils-1.7-4.3.1 zutils-debuginfo-1.7-4.3.1 zutils-debugsource-1.7-4.3.1 - openSUSE Leap 15.0 (x86_64): zutils-1.7-lp150.2.3.1 zutils-debuginfo-1.7-lp150.2.3.1 zutils-debugsource-1.7-lp150.2.3.1 References: https://www.suse.com/security/cve/CVE-2018-1000637.html https://bugzilla.suse.com/1103878 -- . Addresses vulnerability in zutils for openSUSE that permits buffer overflows. Critical update released immediately.. openSUSE,zutils,buffer overrun,security update,patch. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.