Lucene search

K
osvGoogleOSV:ALSA-2022:4991
HistoryJun 13, 2022 - 12:00 a.m.

Important: xz security update

2022-06-1300:00:00
Google
osv.dev
13
xz utils
lzma
compression
vulnerability
patched

AI Score

8.8

Confidence

High

EPSS

0.012

Percentile

85.7%

XZ Utils is an integrated collection of user-space file compression utilities based on the Lempel-Ziv-Markov chain algorithm (LZMA), which performs lossless data compression. The algorithm provides a high compression ratio while keeping the decompression time short.
Security Fix(es):

  • gzip: arbitrary-file-write vulnerability (CVE-2022-1271)
    For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.