Protect yourself against future threats.
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 =========================================================================== AUSCERT External Security Bulletin Redistribution ESB-2022.0366 lrzsz security update 27 January 2022 =========================================================================== AusCERT Security Bulletin Summary --------------------------------- Product: lrzsz Publisher: Debian Operating System: Debian GNU/Linux Impact/Access: Access Confidential Data -- Existing Account Denial of Service -- Existing Account Resolution: Patch/Upgrade CVE Names: CVE-2018-10195 Original Bulletin: https://lists.debian.org/debian-lts-announce/2022/01/msg00027.html - --------------------------BEGIN INCLUDED TEXT-------------------- - -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2900-1 debian-lts@lists.debian.org https://www.debian.org/lts/security/ Thorsten Alteholz January 25, 2022 https://wiki.debian.org/LTS - - ------------------------------------------------------------------------- Package : lrzsz Version : 0.12.21-8+deb9u1 CVE ID : CVE-2018-10195 An issues has been found in lrzsz, a set of tools for zmodem/xmodem/ymodem file transfer. Due to an incorrect length check, which might result in a size_t wrap around, an information leak to the receiving side could happen. For Debian 9 stretch, this problem has been fixed in version 0.12.21-8+deb9u1. We recommend that you upgrade your lrzsz packages. For the detailed security status of lrzsz please refer to its security tracker page at: https://security-tracker.debian.org/tracker/lrzsz Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS - -----BEGIN PGP SIGNATURE----- iQKTBAEBCgB9FiEEYgH7/9u94Hgi6ruWlvysDTh7WEcFAmHwdKpfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDYy MDFGQkZGREJCREUwNzgyMkVBQkI5Njk2RkNBQzBEMzg3QjU4NDcACgkQlvysDTh7 WEfb6w//RtutOLAcIdNhoDpicQmZpdUw8Gh17yqrTUlTd90/0PmAfM0ZC2RDt/yr CgXDZ77vJ8qjo+9IREpzSTR1hQpakSjKVb9a4y9kk1X4Sz0ZxvZugvHZUcou1Yzg JN0hnukhXGwwRHr/JFbOkqm04JUCJ1afcVNuN9x1VPTZybb0NkdbN+35HEobwdXE dsDVwq8bJGuYB12kviv8O0Mhot3g6zd1jQfTJUyvW9MjkuuTSo1eFHJPQ/J53kDr 6St3wRQhPzifjZCdjuMVj1utVj4siALUCBWP5V8VxWDh/ryUfWlbP+481oe78VQU rvfkGMkZSDOAU5KI+37AkdlEgTaLtyY88rHljBDdZGzeMY925cTwSFLECy+RRLer b0j0poV67uTZm5lgnxbSZb40B1CQmmKeY1eisf9FtZc2df6oyKQGGigS2mryXLqb CGY1FPf+X3LoJ+G15M32GiXg4TjWz6wD4VaJh1pLHNnLNDAPE/56xAxO5rZNHfyn yHUNAmzCSl1ftka4gmXmrUaWljFTd+cPayYRJQh4fQK8uk9PGJMYdfwyrmPP8cKz IkBeH8e5qFLkUiYYqriLBgEFC4z5ogQMFEC2iiG1eaKAU6tUvsyCMQFjJeUcbjys T9mjsCDIZfj9lfCWrifiBug3higrXwp3XLKeJw7Uz00a93jHqvk= =qnzT - -----END PGP SIGNATURE----- - --------------------------END INCLUDED TEXT-------------------- You have received this e-mail bulletin as a result of your organisation's registration with AusCERT. The mailing list you are subscribed to is maintained within your organisation, so if you do not wish to continue receiving these bulletins you should contact your local IT manager. If you do not know who that is, please send an email to auscert@auscert.org.au and we will forward your request to the appropriate person. NOTE: Third Party Rights This security bulletin is provided as a service to AusCERT's members. As AusCERT did not write the document quoted above, AusCERT has had no control over its content. The decision to follow or act on information or advice contained in this security bulletin is the responsibility of each user or organisation, and should be considered in accordance with your organisation's site policies and procedures. AusCERT takes no responsibility for consequences which may arise from following or acting on information or advice contained in this security bulletin. NOTE: This is only the original release of the security bulletin. It may not be updated when updates to the original are made. If downloading at a later date, it is recommended that the bulletin is retrieved directly from the author's website to ensure that the information is still current. Contact information for the authors of the original document is included in the Security Bulletin above. If you have any questions or need further information, please contact them directly. Previous advisories and external security bulletins can be retrieved from: https://www.auscert.org.au/bulletins/ =========================================================================== Australian Computer Emergency Response Team The University of Queensland Brisbane Qld 4072 Internet Email: auscert@auscert.org.au Facsimile: (07) 3365 7031 Telephone: (07) 3365 4417 (International: +61 7 3365 4417) AusCERT personnel answer during Queensland business hours which are GMT+10:00 (AEST). On call after hours for member emergencies only. =========================================================================== -----BEGIN PGP SIGNATURE----- Comment: http://www.auscert.org.au/render.html?it=1967 iQIVAwUBYfIj6eNLKJtyKPYoAQg/rg//ZJ2USOUcofoISRpUpYPeOZ4q9ICuDC4k AMPGjoDJQTkYQ42eH5goaE5zBz8Dr1ZNx8kAqr0yuJ869NnmLQAm/KReQ7FQys2D btoVjUdDBbs2NSnk+X3rOZnxZp6dzWNltQqBmmhS59u5PFTUgbqdwXUCw6Nc/qaC vnTkQL+rx5KRlCri4k6kd/t7WhO6HFZcgTH4azPYOL1RwnzxROQW1mF5lDcC3yJQ gClglPB6AgDpuHIXTqcrZH7AXcDX0jG+zde1UmIDVNRLwoFOx7ZlDBBpSPdv4sPl s1637V9m2e56QA9FHeaZ2VkbhxGO7ePfnZJnD21WuoHPmmzP6EXCiAxsTXQwnb+H cQRYYPH8aXhXGaEiRg9dkDmIA0HJ1rgnWTQl6MzoQyVzoR7Yy5jpvQMHljPesZBF kRequ7dgAXZjmozEBA3hEBEOYKfkYoYSX3b/Jama9utJt3Yn6Ug2SjgyvK9poaDO Fr6zcVdW1IPbKpJjsIuZlJj/ncMDEnci4lDH7bPGA1AvwMsPM0ApmZeQS6+lP/9P CeNGp5wfEW7sgqn/2Lr45EGzTdklIBLC+Sg8KCwjpVKNrjJSmlBrdFEO0AjYf0NU Oo0tgzF2BmRD+q27rzBLLa4UCLcXD7CdAViPFFJqqw3UKR0AkysnvUZ245h9AcZf 45HYU6jITIY= =qviC -----END PGP SIGNATURE-----