[ubuntu/bionic-security] cpio 2.12+dfsg-6ubuntu0.18.04.4 (Accepted)

Marc Deslauriers marc.deslauriers at canonical.com
Wed Sep 8 11:11:01 UTC 2021


cpio (2.12+dfsg-6ubuntu0.18.04.4) bionic-security; urgency=medium

  * SECURITY UPDATE: arbitrary code execution via crafted pattern file
    - debian/patches/CVE-2021-38185.patch: rewrite dynamic string support
      in src/copyin.c, src/copyout.c, src/copypass.c, src/dstring.c,
      src/dstring.h, src/util.c.
    - debian/patches/CVE-2021-38185.2.patch: don't call ds_resize in a loop
      in src/dstring.c.
    - debian/patches/CVE-2021-38185.3.patch: fix dynamic string
      reallocations in src/dstring.c.
    - CVE-2021-38185

Date: 2021-08-25 12:04:13.631490+00:00
Changed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
https://launchpad.net/ubuntu/+source/cpio/2.12+dfsg-6ubuntu0.18.04.4
-------------- next part --------------
Sorry, changesfile not available.


More information about the Bionic-changes mailing list