Please read this before reporting a bug:
https://wiki.archlinux.org/title/Bug_reporting_guidelines
Do NOT report bugs when a package is just outdated, or it is in the AUR. Use the 'flag out of date' link on the package page, or the Mailing List.
REPEAT: Do NOT report bugs for outdated packages!
https://wiki.archlinux.org/title/Bug_reporting_guidelines
Do NOT report bugs when a package is just outdated, or it is in the AUR. Use the 'flag out of date' link on the package page, or the Mailing List.
REPEAT: Do NOT report bugs for outdated packages!
FS#71108 - [lrzsz] [Security] information disclosure (CVE-2018-10195)
Attached to Project:
Community Packages
Opened by Jonas Witschel (diabonas) - Wednesday, 02 June 2021, 19:27 GMT
Last edited by Sergej Pupykin (sergej) - Tuesday, 25 January 2022, 14:00 GMT
Opened by Jonas Witschel (diabonas) - Wednesday, 02 June 2021, 19:27 GMT
Last edited by Sergej Pupykin (sergej) - Tuesday, 25 January 2022, 14:00 GMT
|
DetailsSummary
======= The package lrzsz is vulnerable to information disclosure via CVE-2018-10195. Guidance ======== Applying the patch referenced below fixes the issue. References ========== https://security.archlinux.org/AVG-2027 https://bugzilla.redhat.com/show_bug.cgi?id=1572058 https://src.fedoraproject.org/rpms/lrzsz/blob/rawhide/f/lrzsz-0.12.20.patch |
This task depends upon