USN-7414-1: XZ Utils vulnerability
Harri K. Koskinen discovered that XZ Utils incorrectly handled the threaded xz decoder. If a user or automated system were tricked into processing an xz file, a remote attacker could use this issue to cause XZ Utils to crash, resulting in a denial of service, or possibly execute arbitrary code.
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-7414-1?
The security issue identified in USN-7414-1 is considered to be a denial of service vulnerability due to inadequate handling of the threaded xz decoder.
How do I fix USN-7414-1?
To resolve the vulnerability in USN-7414-1, update the xz-utils package to version 5.6.2-2ubuntu0.2 for Ubuntu 24.10 or 5.6.1+really5.4.5-1ubuntu0.2 for Ubuntu 24.04.
What types of attacks are possible due to USN-7414-1?
USN-7414-1 could allow attackers to crash XZ Utils or potentially execute arbitrary code if a user is tricked into processing a malicious xz file.
Which systems are affected by USN-7414-1?
The USN-7414-1 vulnerability affects Ubuntu systems running the xz-utils package versions mentioned in the advisory.
Who discovered the vulnerability in USN-7414-1?
The vulnerability detailed in USN-7414-1 was discovered by Harri K. Koskinen.