SUSE-SU-2023:4424-1
Dashboard / Vulnerabilities / SUSE-SU-2023:4424-1
SUSE-SU-2023:4424-1
Summary: Security update for squashfs
Details: This update for squashfs fixes the following issues: - CVE-2015-4645,CVE-2015-4646: Multiple buffer overflows fixed in squashfs-tools (bsc#935380) - CVE-2021-40153: Fixed an issue where an attacker might have been able to write a file outside of destination (bsc#1189936) - CVE-2021-41072: Fixed an issue where an attacker might have been able to write a file outside the destination directory via a symlink (bsc#1190531).
References: https://www.suse.com/support/update/announcement/2023/suse-su-20234424-1/, https://bugzilla.suse.com/1133284, https://bugzilla.suse.com/1160294, https://bugzilla.suse.com/1189936, https://bugzilla.suse.com/1190531, https://bugzilla.suse.com/935380, https://www.suse.com/security/cve/CVE-2015-4645, https://www.suse.com/security/cve/CVE-2015-4646, https://www.suse.com/security/cve/CVE-2021-40153, https://www.suse.com/security/cve/CVE-2021-41072
Affected packages
Package
Name: squashfs
Purl: pkg:rpm/suse/squashfs&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5
Affected ranges
Type: ECOSYSTEM
Events:
