USN-5078-2
Dashboard / Vulnerabilities / USN-5078-2
USN-5078-2
Summary: squashfs-tools vulnerabilities
Details: USN-5078-1 fixed several vulnerabilities in Squashfs-Tools. This update provides the corresponding update for Ubuntu 16.04 ESM. Original advisory details: Etienne Stalmans discovered that Squashfs-Tools mishandled certain malformed SQUASHFS files. An attacker could use this vulnerability to write arbitrary files to the filesystem. (CVE-2021-40153) Richard Weinberger discovered that Squashfs-Tools mishandled certain malformed SQUASHFS files. An attacker could use this vulnerability to write arbitrary files to the filesystem. (CVE-2021-41072)
References: https://ubuntu.com/security/notices/USN-5078-2, https://ubuntu.com/security/CVE-2021-40153, https://ubuntu.com/security/CVE-2021-41072
Affected packages
Package
Name: squashfs-tools
Purl: pkg:deb/ubuntu/squashfs-tools?arch=source&distro=esm-infra%2Fxenial
Affected ranges
Type: ECOSYSTEM
Events:
