|
|
Subscribe / Log in / New account

Ubuntu alert USN-7656-1 (erlang)

From:  noreply+usn-bot@canonical.com
To:  ubuntu-security-announce@lists.ubuntu.com
Subject:  [USN-7656-1] Erlang vulnerabilities
Date:  Mon, 21 Jul 2025 15:12:38 +0000
Message-ID:  <E1udsBy-0005Ix-QR@lists.ubuntu.com>

========================================================================== Ubuntu Security Notice USN-7656-1 July 21, 2025 erlang vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 25.04 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: Several security issues were fixed in Erlang. Software Description: - erlang: Concurrent, real-time, distributed functional language Details: It was discovered that Erlang OTP’s SSH module incorrectly enforced strict KEX handshake hardening measures. A remote attacker able to intercept communications could possibly use this issue to insert optional messages into connections during the handshake. (CVE-2025-46712) It was discovered that Erlang OTP incorrectly handled ZIP archives. If a user or automated system were tricked into opening a specially crafted ZIP archive, a remote attacker could possibly use this issue to overwrite arbitrary files outside of the intended directory. (CVE-2025-4748) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 25.04 erlang 1:27.3+dfsg-1ubuntu1.2 erlang-ssh 1:27.3+dfsg-1ubuntu1.2 Ubuntu 24.04 LTS erlang 1:25.3.2.8+dfsg-1ubuntu4.4 erlang-ssh 1:25.3.2.8+dfsg-1ubuntu4.4 Ubuntu 22.04 LTS erlang 1:24.2.1+dfsg-1ubuntu0.5 erlang-ssh 1:24.2.1+dfsg-1ubuntu0.5 After a standard system update you need to reboot your computer to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7656-1 CVE-2025-46712, CVE-2025-4748 Package Information: https://launchpad.net/ubuntu/+source/erlang/1:27.3+dfsg-1... https://launchpad.net/ubuntu/+source/erlang/1:25.3.2.8+df... https://launchpad.net/ubuntu/+source/erlang/1:24.2.1+dfsg...


Attachment: signature.asc (type=application/pgp-signature)

-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmh+WNoACgkQcpJm3tlz hgFKeRAAjqF6R61QsnRCLtI9xP/OPlMLz6VF5lD0wXpCOLKDNZDgL9YQOiyrnKdL 4VM2Sgz1h6BINtNf4fE3ulKyPovb1OarKJSC7+BrpougnYIop0nMseLTpOaqBpix w29LxIn4u2Oo065b1kobZuaw6QiopHHE+wwiBiBpN5DdyksLQNouD6k980xgeuro oCWlAgZCMCp1sUCf9sUjqwqRm2+9ARwBseK7Vor3+DTuGBr+XW7dk85h4rSLzgUI 5dyU9ful3PW2kGcOH2aoqu2ag1XJcZgRp42MzAdmDRmSl45HmVT1EFfCow8iC7dW JWmsFSWnb8Yi29G4ck6ruGfUTHUNPpETyxscIfxSMkKpsz+Wwuw6kACE2ws6n2Gn uxI7Cceszn0DlQRtEa5+6CLq3nR4djhTOR9LSEF3cuAsHUcD740aWpO5pyUWtyZY OW6cRsATc7ihhj5/IG4lL5Too5XWEQ/B1OggfVlk5V+ODDg0eFm4Iq15B6UFrwlc CxYQfO0RL+tIczlUspphDC40yDyaXJ5i9HykYTuTgYtBx540DNS5rQYkZGk+9p53 Ma01Rv8dPyX6rKxRSFPleIMov/8wyOz/bHHYmTveZOnckiwnYUjan7mBcYjfrSit RET8ZJs9s8VnyfdmcCKiK4ncxx1HnkuT9zJf33YBSOjhuRrLa7E= =a/4W -----END PGP SIGNATURE-----


to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds