USN-5220-1: Composer vulnerability
8 July 2022
Composer could be made to run programs if it received specially crafted URL values.
Releases
Packages
- composer - dependency manager for PHP
Details
It was discovered that Composer did not properly sanitize URLs for
Mercurial repositories in the root composer.json and package source
download URLs. A remote attacker could possibly use this issue to execute
arbitrary code.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 20.04
-
composer
-
1.10.1-1ubuntu0.1~esm1
Available with Ubuntu Pro
Ubuntu 18.04
-
composer
-
1.6.3-1ubuntu0.1~esm1
Available with Ubuntu Pro
Ubuntu 16.04
-
composer
-
1.0.0~beta2-1ubuntu0.1~esm1
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.