[CLSA-2023:1688070489] Fix CVE(s): CVE-2022-28391
Type:
security
Severity:
Important
Release date:
2023-06-29 20:28:13 UTC
Description:
* SECURITY UPDATE: some applets are vulnerable to escape sequence injection when used from an VT compatible terminal - debian/patches/CVE-2022-28391.patch: sockaddr2str: ensure only printable characters are returned for the hostname part - CVE-2022-28391 * Fix cpio.tests - debian/patches/fix-cpio-tests.patch: set a correct owner
Updated packages:
  • busybox_1.27.2-2ubuntu3.4+tuxcare.els1_amd64.deb
    sha:72f4d736987bf150c9ab2c204375bf7705b1d2f5
  • busybox-initramfs_1.27.2-2ubuntu3.4+tuxcare.els1_amd64.deb
    sha:92b6b6bc0befaf025471746c28aee0516e4ae40f
  • busybox-static_1.27.2-2ubuntu3.4+tuxcare.els1_amd64.deb
    sha:80bb1581c1d3d05608560e42f8a470c80d909008
  • busybox-syslogd_1.27.2-2ubuntu3.4+tuxcare.els1_all.deb
    sha:d61201e59c2732edd84f430638d4a838ecdb00c0
  • udhcpc_1.27.2-2ubuntu3.4+tuxcare.els1_amd64.deb
    sha:16f91d877326586c67aab53ddbab3e5d47642a02
  • udhcpd_1.27.2-2ubuntu3.4+tuxcare.els1_amd64.deb
    sha:6b1661375c3f5f15f82edf071a5c0398606c1b0a
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.