Search CVE reports
1 – 5 of 5 results
CVE-2024-47611
Medium priorityXZ Utils provide a general-purpose data-compression library plus command-line tools. When built for native Windows (MinGW-w64 or MSVC), the command line tools from XZ Utils 5.6.2 and older have a command line argument injection...
1 affected packages
xz-utils
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
xz-utils | Not affected | Not affected | Not affected | Not affected | Not affected |
CVE-2024-3094
Critical priorityMalicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0. Through a series of complex obfuscations, the liblzma build process extracts a prebuilt object file from a disguised test file existing in...
1 affected packages
xz-utils
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
xz-utils | Not affected | Not affected | Not affected | Not affected | Not affected |
CVE-2020-22916
Medium priority** DISPUTED ** An issue discovered in XZ 5.2.5 allows attackers to cause a denial of service via decompression of a crafted file. NOTE: the vendor disputes the claims of "endless output" and "denial of service"...
1 affected packages
xz-utils
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
xz-utils | Not affected | Not affected | Not affected | Not affected | Not affected |
CVE-2022-1271
Medium priorityAn arbitrary file write vulnerability was found in GNU gzip's zgrep utility. When zgrep is applied on the attacker's chosen file name (for example, a crafted file name), this can overwrite an attacker's content to an arbitrary...
2 affected packages
gzip, xz-utils
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
gzip | — | Fixed | Fixed | Fixed | Fixed |
xz-utils | — | Fixed | Fixed | Fixed | Fixed |
CVE-2015-4035
Medium priorityscripts/xzgrep.in in xzgrep 5.2.x before 5.2.0, before 5.0.0 does not properly process file names containing semicolons, which allows remote attackers to execute arbitrary code by having a user run xzgrep on a crafted file name.
1 affected packages
xz-utils
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
xz-utils | — | — | — | — | — |