USN-5078-3
Dashboard / Vulnerabilities / USN-5078-3
USN-5078-3
Summary: squashfs-tools vulnerability
Details: USN-5078-1 fixed a vulnerability in Squashfs-Tools. That update was incomplete and could still result in Squashfs-Tools mishandling certain malformed SQUASHFS files. This update fixes the problem. We apologize for the inconvenience. Original advisory details: Richard Weinberger discovered that Squashfs-Tools mishandled certain malformed SQUASHFS files. An attacker could use this vulnerability to write arbitrary files to the filesystem.
References: https://ubuntu.com/security/notices/USN-5078-3, https://ubuntu.com/security/CVE-2021-41072
Affected packages
Package
Name: squashfs-tools
Purl: pkg:deb/ubuntu/squashfs-tools@1:4.4-1ubuntu0.3?arch=source&distro=focal
Affected ranges
Type: ECOSYSTEM
Events:
