FEDORA-2022-6746dde2a0
Packages in this update:
gzip-1.10-6.fc35
Update description:
zgrep applied to a crafted file name with two or more newlines can no longer overwrite an arbitrary, attacker-selected file.
reproducer:
$ touch foo.gz
$ echo foo | gzip > “$(printf ‘|n;e touch pwnedn#.gz’)”
$ zgrep foo *.gz
(the unfixed version of zgrep creates the file called pwned)
FEDORA-2022-eeb6c686c7
Packages in this update:
gzip-1.11-3.fc36
Update description:
zgrep applied to a crafted file name with two or more newlines can no longer overwrite an arbitrary, attacker-selected file.
reproducer:
$ touch foo.gz
$ echo foo | gzip > “$(printf ‘|n;e touch pwnedn#.gz’)”
$ zgrep foo *.gz
(the unfixed version of zgrep creates the file called pwned)
FEDORA-2022-6b512ae9e5
Packages in this update:
gzip-1.10-5.fc34
Update description:
zgrep applied to a crafted file name with two or more newlines can no longer overwrite an arbitrary, attacker-selected file.
reproducer:
$ touch foo.gz
$ echo foo | gzip > “$(printf ‘|n;e touch pwnedn#.gz’)”
$ zgrep foo *.gz
(the unfixed version of zgrep creates the file called pwned)
FEDORA-2022-05918f0838
Packages in this update:
dhcp-4.4.2-12.b1.fc34
Update description:
Security fix for CVE-2021-25220
FEDORA-2022-dbd2935e44
Packages in this update:
rsync-3.2.3-6.fc34
Update description:
Security fix for CVE-2018-25032
FEDORA-2022-12b89e2aad
Packages in this update:
rsync-3.2.3-15.fc36
Update description:
Security fix for CVE-2018-25032
FEDORA-2022-413a80a102
Packages in this update:
rsync-3.2.3-9.fc35
Update description:
Security fix for CVE-2018-25032
FEDORA-2022-132c6d7c2e
Packages in this update:
rubygem-nokogiri-1.11.7-2.fc34
Update description:
Backport fix for possible DOS by regex assigned as CVE-2022-24836.
FEDORA-2022-9ed7641ce0
Packages in this update:
rubygem-nokogiri-1.13.1-2.fc35
Update description:
Backport fix for possible DOS by regex assigned as CVE-2022-24836.
FEDORA-2022-d231cb5e1f
Packages in this update:
rubygem-nokogiri-1.13.4-1.fc36
Update description:
New version 1.13.4 is released. This new version addresses possible DOS by regex, assigned as CVE-2022-24836.
News, Advisories and much more