-----BEGIN PGP SIGNATURE-----
wsF5BAABCAAjFiEELOLXZEFYQHcSWEHiyfW2m9Ldu6sFAmdQwCYFAwAAAAAACgkQyfW2m9Ldu6sB
gxAAsN4SvoL+NI88gtSpTQyULKIjxiEQ0oLGOqOI0GRXgSjzrfeB7ZyqfsD/P2FmNmtpy0f7m1HF
Jv4DMNvJR0ck+B3lE8c+uF3f6F1zh2v2+8DtL8zDonphmW8FSkwlDzWwtSEfC160I3lEx/WJUnwF
NL65+PIsjzXraoHcqAV35nJhwgPXA1xmF1h7hi00S0yYT0acI7v0XRXRKSqYC6g3XA9SlVfQft2d
qJzpwU+7YW8PU53ZBvkriZxBs5ATsShnBSaiAQtNN3HyRiGYLGbN1EBrZRnwQtLiKhE7Ryyye24P
v8AlQQLxLutV1lsgUd8wJBmdfMRNOMKy0K0kvsb2xlyJ1WaoyhPyXUN3r0FNDsrC7UeEMeZ/W3nu
wqdwknAu2LL0EVYwimu2BPsr9P7o0W7mhYBS95RxQqG/aerFSE3FMWN5sC68GuzEiTyvzBJXY550
BeJNSh2dq8DBwMYpMnlVtsPwFI7K0DU2IsJH6u+I1e1KnZgCPfjwaNPMsodYL9NTpTG8Kn0agBDP
LlhP/XGSNgxxRksAvtzoh0BBGJ9k4Elay6EKGMhMsHUxY6uDK+ysk4KUU6JrixAkih1JTg+FSO0C
Vg+yPYnqvuh4+nNpENJZt866sSoexVwaruzKEa9Nu7G05XBpP5Bpj9FKvOaHht8PP9ons8L2g/pQ
PJ4=
=EOkh
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-7137-1
December 04, 2024
recutils vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS
Summary:
recutils could be made to crash or run programs as a login user if a
specially crafted file was opened.
Software Description:
- recutils: text-based databases called recfiles
Details:
It was discovered that recutils incorrectly handled memory when parsing
comments with the recparser utility. An attacker could possibly use this
issue to cause a denial of service or run arbitrary commands.
(CVE-2021-46019, CVE-2021-46021, CVE-2021-46022)
It was discovered that recutils incorrectly handled memory when parsing CSV
files. An attacker could possibly use this issue to cause a denial of
service or run arbitrary commands. (CVE-2019-11637, CVE-2019-11638,
CVE-2019-11639, CVE-2019-11640)
It was discovered that recutils incorrectly handled memory when parsing
maliciously crafted recfiles. An attacker could possibly use this issue to
cause a denial of service. (CVE-2019-6455, CVE-2019-6456, CVE-2019-6457,
CVE-2019-6458, CVE-2019-6459, CVE-2019-6460)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 22.04 LTS
librec1 1.8-1ubuntu0.22.04.1~esm1
Available with Ubuntu Pro
recutils 1.8-1ubuntu0.22.04.1~esm1
Available with Ubuntu Pro
Ubuntu 20.04 LTS
librec1 1.8-1ubuntu0.20.04.1~esm1
Available with Ubuntu Pro
recutils 1.8-1ubuntu0.20.04.1~esm1
Available with Ubuntu Pro
Ubuntu 18.04 LTS
librec1 1.7-2ubuntu0.1~esm1
Available with Ubuntu Pro
recutils 1.7-2ubuntu0.1~esm1
Available with Ubuntu Pro
Ubuntu 16.04 LTS
librec1 1.7-1ubuntu0.1~esm1
Available with Ubuntu Pro
recutils 1.7-1ubuntu0.1~esm1
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-7137-1
CVE-2019-11637, CVE-2019-11638, CVE-2019-11639, CVE-2019-11640,
CVE-2019-6455, CVE-2019-6456, CVE-2019-6457, CVE-2019-6458,
CVE-2019-6459, CVE-2019-6460, CVE-2021-46019, CVE-2021-46021,
CVE-2021-46022
No comments:
Post a Comment