安全公告详情

NS-SA-2023-0090

2023-05-30 09:08:34

简介

important: xz/udisks2 security update

严重级别

important

主题

An update for xz/udisks2 is now available for NewStart CGSL MAIN 6.06.
NewStart Security has rated this update as having a security impact of important. A Common Vunlnerability Scoring System(CVSS)base score, which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.

详细描述

xz: XZ Utils are an attempt to make LZMA compression easy to use on free (as in freedom) operating systems. This is achieved by providing tools and libraries which are similar to use than the equivalents of the most popular existing compression algorithms. LZMA is a general purpose compression algorithm designed by Igor Pavlov as part of 7-Zip. It provides high compression ratio while keeping the decompression speed fast.
udisks2: This package contains the dynamic library, which provides access to the udisksd daemon.


Security Fix(es):
xz: An arbitrary file write vulnerability was found in GNU gzip's zgrep utility. When zgrep is applied on the attacker's chosen file name (for example, a crafted file name), this can overwrite an attacker's content to an arbitrary attacker-selected file. This flaw occurs due to insufficient validation when processing filenames with two or more newlines where selected content and the target file names are embedded in crafted multi-line file names. This flaw allows a remote, low privileged attacker to force zgrep to write arbitrary files on the system.(CVE-2022-1271)
xz: bugfix
udisks2: A vulnerability found in udisks2. This flaw allows an attacker to input a specially crafted image file/USB leading to kernel panic. The highest threat from this vulnerability is to system availability.(CVE-2021-3802)
udisks2: bugfix


Solution:
For details on how to apply this update, which includes the changes described in this advisory, refer to:
http://security.gd-linux.com/how_to_apply_patch.html
Remember the build tag is 6.06.02B5.

影响组件

  • xz
  • udisks2

影响产品

  • CGSL MAIN 6.06

更新包

{"fix":[{"product":"CGSL MAIN 6.06","pkgs":[{"binary":["xz-5.2.4-4.zncgsl6_6.x86_64.rpm","xz-devel-5.2.4-4.zncgsl6_6.x86_64.rpm","xz-libs-5.2.4-4.zncgsl6_6.x86_64.rpm"],"source":"xz-5.2.4-4.zncgsl6_6.src.rpm"},{"binary":["libudisks2-2.9.0-9.0.1.zncgsl6.x86_64.rpm","udisks2-2.9.0-9.0.1.zncgsl6.x86_64.rpm"],"source":"udisks2-2.9.0-9.0.1.zncgsl6.src.rpm"}]}]}

CVE

参考