USN-7030-1: py7zr vulnerability
Published Sep 24, 2024
·Updated
It was discovered that py7zr was vulnerable to path traversal attacks. If a user or automated system were tricked into extracting a specially crafted 7z archive, an attacker could possibly use this issue to write arbitrary files outside the target directory on the host.
Affected Software
2 affected componentsFixes available
All of the following
ubuntu/python3-py7zr<0.11.3+dfsg-4ubuntu0.1
0.11.3+dfsg-4ubuntu0.1
Ubuntu Ubuntu=22.04
Event History
Sep 24, 2024
Advisory Published
via Ubuntu·12:00 AM
Frequently Asked Questions
1
What is the severity of USN-7030-1?
The severity of USN-7030-1 is considered to be high due to the potential for path traversal attacks.
2
How do I fix USN-7030-1?
To fix USN-7030-1, update python3-py7zr to version 0.11.3+dfsg-4ubuntu0.1 or later.
3
What systems are affected by USN-7030-1?
USN-7030-1 affects Ubuntu 22.04 users who have python3-py7zr installed.
4
What type of attack is described in USN-7030-1?
USN-7030-1 describes a path traversal vulnerability which can allow attackers to write arbitrary files outside the target directory.
5
Is USN-7030-1 related to any specific CVE?
Yes, USN-7030-1 is associated with CVE-2022-44900.