Ubuntu alert USN-7129-1 (TinyGLTF)
From: | Noam Nedelec-Salmon <noam.nedelecsalmon@canonical.com> | |
To: | ubuntu-security-announce@lists.ubuntu.com | |
Subject: | [USN-7129-1] TinyGLTF vulnerability | |
Date: | Tue, 26 Nov 2024 17:02:30 +0100 | |
Message-ID: | <580c8786-aa9c-450c-bbfb-7902d9766e0c@canonical.com> |
========================================================================== Ubuntu Security Notice USN-7129-1 November 26, 2024 TinyGLTF vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 22.04 LTS Summary: TinyGLTF could be made to crash or run programs as your login if it received specially crafted input. Software Description: - tinygltf: glTF loader and saver library Details: It was discovered that TinyGLTF performed file path expansion in an insecure way on certain inputs. An attacker could possibly use this issue to cause a denial of service, or execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 22.04 LTS libtinygltf-dev 2.5.0+dfsg-4ubuntu0.1 libtinygltf1d 2.5.0+dfsg-4ubuntu0.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7129-1 CVE-2022-3008 Package Information: https://launchpad.net/ubuntu/+source/tinygltf/2.5.0+dfsg-...
Attachment: OpenPGP_signature.asc (type=application/pgp-signature)
-----BEGIN PGP SIGNATURE----- wsF5BAABCAAjFiEEio4S3x96YxGyKsfkNfzInf03kcEFAmdF8RYFAwAAAAAACgkQNfzInf03kcEh kQ/+KyNZXQ6AdFuMQVcziJHWxLRzjVwt/YqyK/rM3BdZ2g9c1ofP5/UNTh5Kl7g+yXFtg0nK9XFW +xr83Pj3txFgfwtA6od/2WvkM3kWdwd7s5H24xAxDBnrdT7pGBfaiccd5mUU3asqUNzGjuuKEZPt QSIae0mUzY3vDo3C3omCKJn0IuEHjpsEJCRnteGMVrz1rMsU4efu5awXjEcguDCYAAADluetsG5u t+/SG0ASKWXaGcjxbUtILIuGx+6xJCY4MjjFSxWI0UIfiXZ59lmz0ZeuPZ9bkUptrT3oGqS19vGm 0FyDfsDaxtEN4uy48ELiya4BxzMwSPyr/q0r0bEI2lEBvHyi3LgfleTy2R+veeKhXIkaj3BZM2y7 mEbVw7CYEHvteSDuQR1+9WzxjucmJeHjq5fPBKQnbqocM34w+rMxX1dC7Qas/zxN3QBWvm5tdmSZ 7VO8ZffHg7wpatWvWlDuW7QhGOsC81dB6ozs2yhXEcazYHzQmSeEsCK7Pg4RMR0yCAGGd6Yje9/G jWmL2IesKpSCDOh4zzNn9+7cHbqwztFa5gdA3ipwn2Tq3PvVr66d+6iJ1MSBbY3revzOxhDvAYg1 9XwfQoyW25tmZrua9roMt4yJyQZe66SdK8TyYBcSvyZngd/ZNzSHaOGb7LXdBu2f4V3bOb/YY/e4 bak= =j/fO -----END PGP SIGNATURE-----
Attachment: None (type=text/plain)