squashfs-tools 1:4.4-2ubuntu2 source package in Ubuntu

Changelog

squashfs-tools (1:4.4-2ubuntu2) impish; urgency=medium

  * SECURITY UPDATE: Directory traversal via symlinks in unsquashfs
    - debian/patches/0004-CVE-2021-41072-1.patch: Use
      unsquashfs_closedir() when deleting directories in unsquash-N.c
    - debian/patches/0005-CVE-2021-41072-2.patch: Dynamically allocate
      structure names in unsquash-N.c
    - debian/patches/0006-CVE-2021-41072-3.patch: Store directory names in
      a linked list to allow sorting in unsquash-N.c
    - debian/patches/0007-CVE-2021-41072-4.patch: Sort directory entries in
      squashfs images and treat duplicate directory entries with the same
      name as invalid in unsquash-N.c
    - debian/patches/0008-CVE-2021-41072-5.patch: Fixup Makefile entry for
      unsquash-12.o
    - CVE-2021-41072

 -- Alex Murray <email address hidden>  Tue, 14 Sep 2021 14:58:03 +0930

Upload details

Uploaded by:
Alex Murray
Uploaded to:
Impish
Original maintainer:
Ubuntu Developers
Architectures:
linux-any kfreebsd-any
Section:
kernel
Urgency:
Medium Urgency

See full publishing history Publishing

Series Pocket Published Component Section

Downloads

File Size SHA-256 Checksum
squashfs-tools_4.4.orig.tar.gz 236.2 KiB a7fa4845e9908523c38d4acf92f8a41fdfcd19def41bd5090d7ad767a6dc75c3
squashfs-tools_4.4-2ubuntu2.debian.tar.xz 17.4 KiB ddec8c68c51b626a013f0190f44b8173a43d1ca514d4f625d4850c54790ad5f2
squashfs-tools_4.4-2ubuntu2.dsc 1.6 KiB 2c646910d3694a4ac33e727733d661c1e4471516ec774a81ebcc11a8c788a2a9

View changes file

Binary packages built by this source

squashfs-tools: Tool to create and append to squashfs filesystems

 Squashfs is a highly compressed read-only filesystem for Linux. It uses zlib
 compression to compress both files, inodes and directories. Inodes in the
 system are very small and all blocks are packed to minimise data overhead.
 Block sizes greater than 4K are supported up to a maximum of 64K.
 .
 Squashfs is intended for general read-only filesystem use, for archival use
 (i.e. in cases where a .tar.gz file may be used), and in constrained block
 device/memory systems (e.g. embedded systems) where low overhead is needed.

squashfs-tools-dbgsym: No summary available for squashfs-tools-dbgsym in ubuntu impish.

No description available for squashfs-tools-dbgsym in ubuntu impish.