Описание
Security update for gzip
This update for gzip fixes the following issues:
- CVE-2022-1271: Add hardening for zgrep. (bsc#1198062)
Список пакетов
Image SLES12-SP5-Azure-BYOS
gzip-1.10-4.14.1
Image SLES12-SP5-Azure-Basic-On-Demand
gzip-1.10-4.14.1
Image SLES12-SP5-Azure-HPC-BYOS
gzip-1.10-4.14.1
Image SLES12-SP5-Azure-HPC-On-Demand
gzip-1.10-4.14.1
Image SLES12-SP5-Azure-SAP-BYOS
gzip-1.10-4.14.1
Image SLES12-SP5-Azure-SAP-On-Demand
gzip-1.10-4.14.1
Image SLES12-SP5-Azure-Standard-On-Demand
gzip-1.10-4.14.1
Image SLES12-SP5-EC2-BYOS
gzip-1.10-4.14.1
Image SLES12-SP5-EC2-ECS-On-Demand
gzip-1.10-4.14.1
Image SLES12-SP5-EC2-On-Demand
gzip-1.10-4.14.1
Image SLES12-SP5-EC2-SAP-BYOS
gzip-1.10-4.14.1
Image SLES12-SP5-EC2-SAP-On-Demand
gzip-1.10-4.14.1
Image SLES12-SP5-GCE-BYOS
gzip-1.10-4.14.1
Image SLES12-SP5-GCE-On-Demand
gzip-1.10-4.14.1
Image SLES12-SP5-GCE-SAP-BYOS
gzip-1.10-4.14.1
Image SLES12-SP5-GCE-SAP-On-Demand
gzip-1.10-4.14.1
Image SLES12-SP5-SAP-Azure-LI-BYOS-Production
gzip-1.10-4.14.1
Image SLES12-SP5-SAP-Azure-VLI-BYOS-Production
gzip-1.10-4.14.1
SUSE Linux Enterprise Server 12 SP5
gzip-1.10-4.14.1
SUSE Linux Enterprise Server for SAP Applications 12 SP5
gzip-1.10-4.14.1
Ссылки
- Link for SUSE-SU-2022:1650-1
- E-Mail link for SUSE-SU-2022:1650-1
- SUSE Security Ratings
- SUSE CVE CVE-2022-1271 page
Описание
An arbitrary file write vulnerability was found in GNU gzip's zgrep utility. When zgrep is applied on the attacker's chosen file name (for example, a crafted file name), this can overwrite an attacker's content to an arbitrary attacker-selected file. This flaw occurs due to insufficient validation when processing filenames with two or more newlines where selected content and the target file names are embedded in crafted multi-line file names. This flaw allows a remote, low privileged attacker to force zgrep to write arbitrary files on the system.
Затронутые продукты
Image SLES12-SP5-Azure-BYOS:gzip-1.10-4.14.1
Image SLES12-SP5-Azure-Basic-On-Demand:gzip-1.10-4.14.1
Image SLES12-SP5-Azure-HPC-BYOS:gzip-1.10-4.14.1
Image SLES12-SP5-Azure-HPC-On-Demand:gzip-1.10-4.14.1
Ссылки
- CVE-2022-1271
- SUSE Bug 1198062
- SUSE Bug 1198812
- SUSE Bug 1199107
- SUSE Bug 1199108