Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2022:1250-1

Опубликовано: 17 апр. 2022
Источник: suse-cvrf

Описание

Security update for gzip

This update for gzip fixes the following issues:

  • CVE-2022-1271: Fixed an incorrect escaping of malicious filenames (ZDI-CAN-16587). (bsc#1198062)

The following non-security bugs were fixed:

  • Fixed an issue when 'gzexe' counts the lines to skip wrong. (bsc#1180713)
  • Fixed a potential segfault when zlib acceleration is enabled (bsc#1177047)

Список пакетов

Container caasp/v4/cilium:1.6.6
gzip-1.10-150000.4.12.1
Container ses/6/cephcsi/cephcsi:latest
gzip-1.10-150000.4.12.1
Image SLES15-Azure-BYOS
gzip-1.10-150000.4.12.1
Image SLES15-SAP-Azure-BYOS
gzip-1.10-150000.4.12.1
Image SLES15-SAP-Azure-LI-BYOS-Production
gzip-1.10-150000.4.12.1
Image SLES15-SAP-Azure-VLI-BYOS-Production
gzip-1.10-150000.4.12.1
Image SLES15-SP1-Azure-BYOS
gzip-1.10-150000.4.12.1
Image SLES15-SP1-Azure-HPC-BYOS
gzip-1.10-150000.4.12.1
Image SLES15-SP1-CHOST-BYOS-Azure
gzip-1.10-150000.4.12.1
Image SLES15-SP1-CHOST-BYOS-EC2
gzip-1.10-150000.4.12.1
Image SLES15-SP1-CHOST-BYOS-GCE
gzip-1.10-150000.4.12.1
Image SLES15-SP1-SAP-Azure-BYOS
gzip-1.10-150000.4.12.1
Image SLES15-SP1-SAP-Azure-LI-BYOS-Production
gzip-1.10-150000.4.12.1
Image SLES15-SP1-SAP-Azure-VLI-BYOS-Production
gzip-1.10-150000.4.12.1
Image SLES15-SP1-SAPCAL-Azure
gzip-1.10-150000.4.12.1
Image SLES15-SP1-SAPCAL-EC2-HVM
gzip-1.10-150000.4.12.1
Image SLES15-SP1-SAPCAL-GCE
gzip-1.10-150000.4.12.1
SUSE Enterprise Storage 6
gzip-1.10-150000.4.12.1
SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS
gzip-1.10-150000.4.12.1
SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS
gzip-1.10-150000.4.12.1
SUSE Linux Enterprise High Performance Computing 15-ESPOS
gzip-1.10-150000.4.12.1
SUSE Linux Enterprise High Performance Computing 15-LTSS
gzip-1.10-150000.4.12.1
SUSE Linux Enterprise Server 15 SP1-BCL
gzip-1.10-150000.4.12.1
SUSE Linux Enterprise Server 15 SP1-LTSS
gzip-1.10-150000.4.12.1
SUSE Linux Enterprise Server 15-LTSS
gzip-1.10-150000.4.12.1
SUSE Linux Enterprise Server for SAP Applications 15
gzip-1.10-150000.4.12.1
SUSE Linux Enterprise Server for SAP Applications 15 SP1
gzip-1.10-150000.4.12.1

Описание

An arbitrary file write vulnerability was found in GNU gzip's zgrep utility. When zgrep is applied on the attacker's chosen file name (for example, a crafted file name), this can overwrite an attacker's content to an arbitrary attacker-selected file. This flaw occurs due to insufficient validation when processing filenames with two or more newlines where selected content and the target file names are embedded in crafted multi-line file names. This flaw allows a remote, low privileged attacker to force zgrep to write arbitrary files on the system.


Затронутые продукты
Container caasp/v4/cilium:1.6.6:gzip-1.10-150000.4.12.1
Container ses/6/cephcsi/cephcsi:latest:gzip-1.10-150000.4.12.1
Image SLES15-Azure-BYOS:gzip-1.10-150000.4.12.1
Image SLES15-SAP-Azure-BYOS:gzip-1.10-150000.4.12.1

Ссылки