ZeroHour
oss-securitypublished ()ingested

Fwd: XZ Utils 5.8.4 and a security fix

mediumVulnerabilityimportance 45
AI summary · glm-5.3-flash

XZ Utils 5.8.4 fixes an invalid memory write that occurs when a decoder is reinitialized after allocation failure in 5.8.3 and older.

XZ Utils 5.8.4 has been released with a security fix for versions 5.8.3 and older. The flaw is an invalid memory write that can occur when a decoder is reinitialized after an allocation failure. The announcement was posted on the oss-security mailing list by Sam James pointing to the upstream stable release. Users and distributions running affected versions should upgrade to 5.8.4.

  • Fixed in XZ Utils 5.8.4; affected versions are 5.8.3 and older.
  • Triggered when a decoder is reinitialized following an allocation failure.
  • Announced via the oss-security mailing list with details on the Tukaani project page.
VendorsXZ Utils
ProductsXZ Utils
OrganizationsTukaani
Full article

Posted by Sam James on Sep 09 -------------------- Start of forwarded message -------------------- https://tukaani.org/xz/#_stable>. In XZ Utils 5.8.3 and older, an invalid memory write can occur if a decoder is reinitialized after allocation failure. For details, see the...

This source does not provide full text. Read it at seclists.org.