CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
Percentile
85.7%
Medium
Canonical Ubuntu
Cleemy Desu Wayo discovered that Gzip incorrectly handled certain filenames. If a user or automated system were tricked into performing zgrep operations with specially crafted filenames, a remote attacker could overwrite arbitrary files. Update Instructions: Run sudo ua fix USN-5378-1
to fix the vulnerability. The problem can be corrected by updating your system to the following package versions: gzip – 1.6-5ubuntu1.2 gzip-win32 – 1.6-5ubuntu1.2 No subscription required
CVEs contained in this USN include: CVE-2022-1271.
Severity is medium unless otherwise noted.
Users of affected products are strongly encouraged to follow the mitigations below.
The Cloud Foundry project recommends upgrading the following releases:
2022-05-23: Initial vulnerability report published.
Vendor | Product | Version | CPE |
---|---|---|---|
cloudfoundry | bionic_stemcells | * | cpe:2.3:a:cloudfoundry:bionic_stemcells:*:*:*:*:*:*:*:* |
cloudfoundry | cflinuxfs3 | * | cpe:2.3:a:cloudfoundry:cflinuxfs3:*:*:*:*:*:*:*:* |
cloudfoundry | cf-deployment | * | cpe:2.3:a:cloudfoundry:cf-deployment:*:*:*:*:*:*:*:* |