USN-4811-1: libzip vulnerability
15 March 2021
libzip could be made to crash or run programs if it received specially crafted ZIP archives.
Releases
Packages
- libzip - library for reading, creating, and modifying zip archives
Details
It was discovered that libzip mishandled certain malformed ZIP archives.
A remote attacker could use this vulnerability to cause a denial of service.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 18.04
-
ziptool
-
1.1.2-1.1ubuntu0.1~esm1
Available with Ubuntu Pro
-
libzip4
-
1.1.2-1.1ubuntu0.1~esm1
Available with Ubuntu Pro
Ubuntu 16.04
-
libzip4
-
1.0.1-0ubuntu1.1~esm1
Available with Ubuntu Pro
-
zipcmp
-
1.0.1-0ubuntu1.1~esm1
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.