Mageia alert MGASA-2022-0049 (lrzsz)
From: | Mageia Updates <buildsystem-daemon@mageia.org> | |
To: | updates-announce@ml.mageia.org | |
Subject: | [updates-announce] MGASA-2022-0049: Updated lrzsz packages fix security vulnerability | |
Date: | Sat, 05 Feb 2022 21:24:05 +0100 | |
Message-ID: | <20220205202405.5B9969FF0B@duvel.mageia.org> | |
Archive-link: | Article |
MGASA-2022-0049 - Updated lrzsz packages fix security vulnerability Publication date: 05 Feb 2022 URL: https://advisories.mageia.org/MGASA-2022-0049.html Type: security Affected Mageia releases: 8 CVE: CVE-2018-10195 Description: lrzsz before version 0.12.21~rc can leak information to the receiving side due to an incorrect length check in the function zsdata that causes a size_t to wrap around. (CVE-2018-10195) References: - https://bugs.mageia.org/show_bug.cgi?id=29970 - https://www.debian.org/lts/security/2022/dla-2900 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1... SRPMS: - 8/core/lrzsz-0.12.21-23.1.mga8