[ubuntu/hirsute-security] cpio 2.13+dfsg-4ubuntu0.3 (Accepted)

Marc Deslauriers marc.deslauriers at canonical.com
Wed Sep 8 11:10:58 UTC 2021


cpio (2.13+dfsg-4ubuntu0.3) hirsute-security; urgency=medium

  * SECURITY UPDATE: arbitrary code execution via crafted pattern file
    - debian/patches/CVE-2021-38185.patch: rewrite dynamic string support
      in src/copyin.c, src/copyout.c, src/copypass.c, src/dstring.c,
      src/dstring.h, src/util.c.
    - debian/patches/CVE-2021-38185.2.patch: don't call ds_resize in a loop
      in src/dstring.c.
    - debian/patches/CVE-2021-38185.3.patch: fix dynamic string
      reallocations in src/dstring.c.
    - CVE-2021-38185

Date: 2021-08-25 12:12:10.086123+00:00
Changed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
https://launchpad.net/ubuntu/+source/cpio/2.13+dfsg-4ubuntu0.3
-------------- next part --------------
Sorry, changesfile not available.


More information about the Hirsute-changes mailing list