Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2022:1275-1

Опубликовано: 20 апр. 2022
Источник: suse-cvrf

Описание

Security update for gzip

This update for gzip fixes the following issues:

  • CVE-2022-1271: Fixed an incorrect escaping of malicious filenames (ZDI-CAN-16587). (bsc#1198062)

Список пакетов

Container suse/sles12sp3:latest
gzip-1.6-9.6.2
HPE Helion OpenStack 8
gzip-1.6-9.6.2
Image SLES12-SP4-Azure-BYOS
gzip-1.6-9.6.2
Image SLES12-SP4-SAP-Azure-BYOS
gzip-1.6-9.6.2
Image SLES12-SP4-SAP-Azure-LI-BYOS-Production
gzip-1.6-9.6.2
Image SLES12-SP4-SAP-Azure-VLI-BYOS-Production
gzip-1.6-9.6.2
SUSE Linux Enterprise Server 12 SP2-BCL
gzip-1.6-9.6.2
SUSE Linux Enterprise Server 12 SP3-BCL
gzip-1.6-9.6.2
SUSE Linux Enterprise Server 12 SP3-LTSS
gzip-1.6-9.6.2
SUSE Linux Enterprise Server 12 SP4-LTSS
gzip-1.6-9.6.2
SUSE Linux Enterprise Server for SAP Applications 12 SP3
gzip-1.6-9.6.2
SUSE Linux Enterprise Server for SAP Applications 12 SP4
gzip-1.6-9.6.2
SUSE OpenStack Cloud 8
gzip-1.6-9.6.2
SUSE OpenStack Cloud 9
gzip-1.6-9.6.2
SUSE OpenStack Cloud Crowbar 8
gzip-1.6-9.6.2
SUSE OpenStack Cloud Crowbar 9
gzip-1.6-9.6.2

Описание

An arbitrary file write vulnerability was found in GNU gzip's zgrep utility. When zgrep is applied on the attacker's chosen file name (for example, a crafted file name), this can overwrite an attacker's content to an arbitrary attacker-selected file. This flaw occurs due to insufficient validation when processing filenames with two or more newlines where selected content and the target file names are embedded in crafted multi-line file names. This flaw allows a remote, low privileged attacker to force zgrep to write arbitrary files on the system.


Затронутые продукты
Container suse/sles12sp3:latest:gzip-1.6-9.6.2
HPE Helion OpenStack 8:gzip-1.6-9.6.2
Image SLES12-SP4-Azure-BYOS:gzip-1.6-9.6.2
Image SLES12-SP4-SAP-Azure-BYOS:gzip-1.6-9.6.2

Ссылки