gzip 1.10-4ubuntu1.1 source package in Ubuntu

Changelog

gzip (1.10-4ubuntu1.1) impish-security; urgency=medium

  * SECURITY UPDATE: arbitrary file override with crafted file names
    - debian/patches/CVE-2022-1271-1.patch: avoid exploit via multi-newline
      file names in zgrep.in.
    - debian/patches/CVE-2022-1271-2.patch: add test in tests/Makefile.am,
      tests/zgrep-abuse.
    - debian/patches/CVE-2022-1271-3.patch: port to POSIX sed in zgrep.in.
    - debian/patches/CVE-2022-1271-4.patch: optimize out a grep in
      gzexe.in.
    - debian/patches/CVE-2022-1271-5.patch: use C locale more often in
      gzexe.in, sample/zfile, zdiff.in, zgrep.in, znew.in.
    - debian/patches/CVE-2022-1271-6.patch: fix "binary file matches"
      mislabeling in tests/Makefile.am, tests/zgrep-binary, zgrep.in.
    - debian/rules: fix permissions on new test scripts.
    - CVE-2022-1271

 -- Marc Deslauriers <email address hidden>  Fri, 08 Apr 2022 07:04:04 -0400

Upload details

Uploaded by:
Marc Deslauriers
Uploaded to:
Impish
Original maintainer:
Ubuntu Developers
Architectures:
any all
Section:
utils
Urgency:
Medium Urgency

See full publishing history Publishing

Series Pocket Published Component Section

Downloads

File Size SHA-256 Checksum
gzip_1.10.orig.tar.gz 1.1 MiB c91f74430bf7bc20402e1f657d0b252cb80aa66ba333a25704512af346633c68
gzip_1.10.orig.tar.gz.asc 833 bytes b5e4942cca901ca37772d3ea060c4af6a1908719cec5327fbe033f9d30933f1b
gzip_1.10-4ubuntu1.1.debian.tar.xz 38.0 KiB ed6b257d2a9770d3292f5688c1a9b65e94ce6e87d7a79942cb636bc134646209
gzip_1.10-4ubuntu1.1.dsc 2.2 KiB 3b30302238dfedecd9bcfdc9e3df07efef2bee30323abaee61114d6b58097815

View changes file

Binary packages built by this source

gzip: No summary available for gzip in ubuntu impish.

No description available for gzip in ubuntu impish.

gzip-dbgsym: No summary available for gzip-dbgsym in ubuntu impish.

No description available for gzip-dbgsym in ubuntu impish.

gzip-win32: No summary available for gzip-win32 in ubuntu impish.

No description available for gzip-win32 in ubuntu impish.