ALASMONO-2023-001

Related Vulnerabilities: CVE-2021-32840  

SharpZipLib (or #ziplib) is a Zip, GZip, Tar and BZip2 library. Prior to version 1.3.3, a TAR file entry `../evil.txt` may be extracted in the parent directory of `destFolder`. This leads to arbitrary file write that may lead to code execution. The vulnerability was patched in version 1.3.3. (CVE-2021-32840)

ALASMONO-2023-001


Amazon Linux 2 Security Advisory: ALASMONO-2023-001
Advisory Release Date: 2023-08-04 20:34 Pacific
Advisory Updated Date: 2023-09-25 22:09 Pacific
Severity: Important

Issue Overview:

SharpZipLib (or #ziplib) is a Zip, GZip, Tar and BZip2 library. Prior to version 1.3.3, a TAR file entry `../evil.txt` may be extracted in the parent directory of `destFolder`. This leads to arbitrary file write that may lead to code execution. The vulnerability was patched in version 1.3.3. (CVE-2021-32840)


Affected Packages:

mono


Issue Correction:
Run yum update mono to update your system.

New Packages:
aarch64:
    mono-core-6.12.0-5.amzn2.0.1.aarch64
    mono-winfx-6.12.0-5.amzn2.0.1.aarch64
    mono-mvc-6.12.0-5.amzn2.0.1.aarch64
    mono-mvc-devel-6.12.0-5.amzn2.0.1.aarch64
    mono-devel-6.12.0-5.amzn2.0.1.aarch64
    mono-locale-extras-6.12.0-5.amzn2.0.1.aarch64
    mono-extras-6.12.0-5.amzn2.0.1.aarch64
    mono-reactive-6.12.0-5.amzn2.0.1.aarch64
    mono-reactive-winforms-6.12.0-5.amzn2.0.1.aarch64
    mono-reactive-devel-6.12.0-5.amzn2.0.1.aarch64
    mono-winforms-6.12.0-5.amzn2.0.1.aarch64
    mono-wcf-6.12.0-5.amzn2.0.1.aarch64
    mono-web-6.12.0-5.amzn2.0.1.aarch64
    mono-web-devel-6.12.0-5.amzn2.0.1.aarch64
    mono-data-6.12.0-5.amzn2.0.1.aarch64
    mono-data-sqlite-6.12.0-5.amzn2.0.1.aarch64
    mono-data-oracle-6.12.0-5.amzn2.0.1.aarch64
    ibm-data-db2-6.12.0-5.amzn2.0.1.aarch64
    monodoc-6.12.0-5.amzn2.0.1.aarch64
    monodoc-devel-6.12.0-5.amzn2.0.1.aarch64
    mono-complete-6.12.0-5.amzn2.0.1.aarch64
    mono-debuginfo-6.12.0-5.amzn2.0.1.aarch64

i686:
    mono-core-6.12.0-5.amzn2.0.1.i686
    mono-winfx-6.12.0-5.amzn2.0.1.i686
    mono-mvc-6.12.0-5.amzn2.0.1.i686
    mono-mvc-devel-6.12.0-5.amzn2.0.1.i686
    mono-devel-6.12.0-5.amzn2.0.1.i686
    mono-locale-extras-6.12.0-5.amzn2.0.1.i686
    mono-extras-6.12.0-5.amzn2.0.1.i686
    mono-reactive-6.12.0-5.amzn2.0.1.i686
    mono-reactive-winforms-6.12.0-5.amzn2.0.1.i686
    mono-reactive-devel-6.12.0-5.amzn2.0.1.i686
    mono-winforms-6.12.0-5.amzn2.0.1.i686
    mono-wcf-6.12.0-5.amzn2.0.1.i686
    mono-web-6.12.0-5.amzn2.0.1.i686
    mono-web-devel-6.12.0-5.amzn2.0.1.i686
    mono-data-6.12.0-5.amzn2.0.1.i686
    mono-data-sqlite-6.12.0-5.amzn2.0.1.i686
    mono-data-oracle-6.12.0-5.amzn2.0.1.i686
    ibm-data-db2-6.12.0-5.amzn2.0.1.i686
    monodoc-6.12.0-5.amzn2.0.1.i686
    monodoc-devel-6.12.0-5.amzn2.0.1.i686
    mono-complete-6.12.0-5.amzn2.0.1.i686
    mono-debuginfo-6.12.0-5.amzn2.0.1.i686

src:
    mono-6.12.0-5.amzn2.0.1.src

x86_64:
    mono-core-6.12.0-5.amzn2.0.1.x86_64
    mono-winfx-6.12.0-5.amzn2.0.1.x86_64
    mono-mvc-6.12.0-5.amzn2.0.1.x86_64
    mono-mvc-devel-6.12.0-5.amzn2.0.1.x86_64
    mono-devel-6.12.0-5.amzn2.0.1.x86_64
    mono-locale-extras-6.12.0-5.amzn2.0.1.x86_64
    mono-extras-6.12.0-5.amzn2.0.1.x86_64
    mono-reactive-6.12.0-5.amzn2.0.1.x86_64
    mono-reactive-winforms-6.12.0-5.amzn2.0.1.x86_64
    mono-reactive-devel-6.12.0-5.amzn2.0.1.x86_64
    mono-winforms-6.12.0-5.amzn2.0.1.x86_64
    mono-wcf-6.12.0-5.amzn2.0.1.x86_64
    mono-web-6.12.0-5.amzn2.0.1.x86_64
    mono-web-devel-6.12.0-5.amzn2.0.1.x86_64
    mono-data-6.12.0-5.amzn2.0.1.x86_64
    mono-data-sqlite-6.12.0-5.amzn2.0.1.x86_64
    mono-data-oracle-6.12.0-5.amzn2.0.1.x86_64
    ibm-data-db2-6.12.0-5.amzn2.0.1.x86_64
    monodoc-6.12.0-5.amzn2.0.1.x86_64
    monodoc-devel-6.12.0-5.amzn2.0.1.x86_64
    mono-complete-6.12.0-5.amzn2.0.1.x86_64
    mono-debuginfo-6.12.0-5.amzn2.0.1.x86_64