[ubuntu/impish-security] xz-utils 5.2.5-2ubuntu0.1 (Accepted)

Marc Deslauriers marc.deslauriers at canonical.com
Wed Apr 13 12:41:16 UTC 2022


xz-utils (5.2.5-2ubuntu0.1) impish-security; urgency=medium

  * SECURITY UPDATE: arbitrary file overwrite or code execution with
    crafted file names
    - debian/patches/CVE-2022-1271.patch: fix escaping of malicious
      filenames in src/scripts/xzgrep.in.
    - CVE-2022-1271

Date: 2022-04-08 13:45:10.568654+00:00
Changed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
https://launchpad.net/ubuntu/+source/xz-utils/5.2.5-2ubuntu0.1
-------------- next part --------------
Sorry, changesfile not available.


More information about the impish-changes mailing list