USN-6569-1: libclamunrar vulnerabilities
it was discovered that libclamunrar incorrectly handled directories when extracting RAR archives. A remote attacker could possibly use this issue to overwrite arbitrary files and execute arbitrary code. This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 23.04. (CVE-2022-30333) It was discovered that libclamunrar incorrectly validated certain structures when extracting RAR archives. A remote attacker could possibly use this issue to execute arbitrary code. (CVE-2023-40477)
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-6569-1?
The severity of USN-6569-1 is critical due to the potential for arbitrary file overwrite and execution of arbitrary code.
How do I fix USN-6569-1?
To fix USN-6569-1, update the affected package 'libclamunrar11' or 'libclamunrar9' to the latest version specified in your Ubuntu release.
Which Ubuntu versions are affected by USN-6569-1?
The affected Ubuntu versions for USN-6569-1 are 20.04 LTS, 22.04 LTS, and 23.04.
Can USN-6569-1 lead to remote code execution?
Yes, USN-6569-1 could potentially allow a remote attacker to execute arbitrary code on the affected systems.
What packages are specifically related to USN-6569-1?
The packages related to USN-6569-1 are 'libclamunrar11' for Ubuntu 23.10 and 'libclamunrar9' for the other affected versions.