squashfs-tools 1:4.4-2ubuntu0.2 source package in Ubuntu

Changelog

squashfs-tools (1:4.4-2ubuntu0.2) hirsute-security; urgency=medium

  * SECURITY UPDATE: Directory traversal via symlinks in unsquashfs
    - debian/patches/0004-CVE-2021-41072-1.patch: Use
      unsquashfs_closedir() when deleting directories in unsquash-N.c
    - debian/patches/0005-CVE-2021-41072-2.patch: Dynamically allocate
      structure names in unsquash-N.c
    - debian/patches/0006-CVE-2021-41072-3.patch: Store directory names in
      a linked list to allow sorting in unsquash-N.c
    - debian/patches/0007-CVE-2021-41072-4.patch: Sort directory entries in
      squashfs images and treat duplicate directory entries with the same
      name as invalid in unsquash-N.c
    - debian/patches/0008-CVE-2021-41072-5.patch: Fixup Makefile entry for
      unsquash-12.o
    - CVE-2021-41072

 -- Alex Murray <email address hidden>  Tue, 14 Sep 2021 16:41:35 +0930

Upload details

Uploaded by:
Alex Murray
Uploaded to:
Hirsute
Original maintainer:
Ubuntu Developers
Architectures:
linux-any kfreebsd-any
Section:
kernel
Urgency:
Medium Urgency

See full publishing history Publishing

Series Pocket Published Component Section

Downloads

File Size SHA-256 Checksum
squashfs-tools_4.4.orig.tar.gz 236.2 KiB a7fa4845e9908523c38d4acf92f8a41fdfcd19def41bd5090d7ad767a6dc75c3
squashfs-tools_4.4-2ubuntu0.2.debian.tar.xz 17.4 KiB 89fa22e4ba0b1a4194c73d64a09a8d7d1a8a33984b5a6350e7881f5f97b12f82
squashfs-tools_4.4-2ubuntu0.2.dsc 1.7 KiB 2150b636d085743b685b1e42542fe7c35746a7a07178d157d66c0e3b2cb53442

View changes file

Binary packages built by this source

squashfs-tools: No summary available for squashfs-tools in ubuntu hirsute.

No description available for squashfs-tools in ubuntu hirsute.

squashfs-tools-dbgsym: No summary available for squashfs-tools-dbgsym in ubuntu hirsute.

No description available for squashfs-tools-dbgsym in ubuntu hirsute.