First published: Thu Jul 04 2019(Updated: )
USN-4038-1 fixed a vulnerability in bzip2. The update introduced a regression causing bzip2 to incorrect raises CRC errors for some files. This update provides the corresponding update for Ubuntu 12.04 ESM and 14.04 ESM. We apologize for the inconvenience. Original advisory details: It was discovered that bzip2 incorrectly handled certain files. An attacker could possibly use this issue to execute arbitrary code.
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/bzip2 | <1.0.6-5ubuntu0.1~esm2 | 1.0.6-5ubuntu0.1~esm2 |
Ubuntu OpenSSH Client | =14.04 | |
All of | ||
ubuntu/lib32bz2-1.0 | <1.0.6-5ubuntu0.1~esm2 | 1.0.6-5ubuntu0.1~esm2 |
Ubuntu OpenSSH Client | =14.04 | |
All of | ||
ubuntu/lib64bz2-1.0 | <1.0.6-5ubuntu0.1~esm2 | 1.0.6-5ubuntu0.1~esm2 |
Ubuntu OpenSSH Client | =14.04 | |
All of | ||
ubuntu/libbz2-1.0 | <1.0.6-5ubuntu0.1~esm2 | 1.0.6-5ubuntu0.1~esm2 |
Ubuntu OpenSSH Client | =14.04 | |
All of | ||
ubuntu/bzip2 | <1.0.6-1ubuntu0.2 | 1.0.6-1ubuntu0.2 |
Ubuntu OpenSSH Client | =12.04 | |
All of | ||
ubuntu/lib32bz2-1.0 | <1.0.6-1ubuntu0.2 | 1.0.6-1ubuntu0.2 |
Ubuntu OpenSSH Client | =12.04 | |
All of | ||
ubuntu/lib64bz2-1.0 | <1.0.6-1ubuntu0.2 | 1.0.6-1ubuntu0.2 |
Ubuntu OpenSSH Client | =12.04 | |
All of | ||
ubuntu/libbz2-1.0 | <1.0.6-1ubuntu0.2 | 1.0.6-1ubuntu0.2 |
Ubuntu OpenSSH Client | =12.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The title of this vulnerability is USN-4038-4: bzip2 regression.
This vulnerability is a regression in the bzip2 package, causing CRC errors to occur incorrectly for some files.
Ubuntu 12.04 and 14.04 are affected by this vulnerability.
To fix this vulnerability, update the bzip2 package to version 1.0.6-5ubuntu0.1~esm2 for Ubuntu 12.04 ESM and 14.04 ESM.
You can find more information about this vulnerability in the Ubuntu Security Notice USN-4038-4 and the corresponding bug reports.