Amazon Linux 2 Security Advisory: ALASMONO-2023-001
Advisory Release Date: 2023-08-04 20:34 Pacific
Advisory Updated Date: 2023-09-25 22:09 Pacific
SharpZipLib (or #ziplib) is a Zip, GZip, Tar and BZip2 library. Prior to version 1.3.3, a TAR file entry `../evil.txt` may be extracted in the parent directory of `destFolder`. This leads to arbitrary file write that may lead to code execution. The vulnerability was patched in version 1.3.3. (CVE-2021-32840)
Affected Packages:
mono
Note:
This advisory is applicable to Amazon Linux 2 - Mono Extra. Visit this page to learn more about Amazon Linux 2 (AL2) Extras and this FAQ section for the difference between AL2 Core and AL2 Extras advisories.
Issue Correction:
Run yum update mono to update your system.
aarch64:
mono-core-6.12.0-5.amzn2.0.1.aarch64
mono-winfx-6.12.0-5.amzn2.0.1.aarch64
mono-mvc-6.12.0-5.amzn2.0.1.aarch64
mono-mvc-devel-6.12.0-5.amzn2.0.1.aarch64
mono-devel-6.12.0-5.amzn2.0.1.aarch64
mono-locale-extras-6.12.0-5.amzn2.0.1.aarch64
mono-extras-6.12.0-5.amzn2.0.1.aarch64
mono-reactive-6.12.0-5.amzn2.0.1.aarch64
mono-reactive-winforms-6.12.0-5.amzn2.0.1.aarch64
mono-reactive-devel-6.12.0-5.amzn2.0.1.aarch64
mono-winforms-6.12.0-5.amzn2.0.1.aarch64
mono-wcf-6.12.0-5.amzn2.0.1.aarch64
mono-web-6.12.0-5.amzn2.0.1.aarch64
mono-web-devel-6.12.0-5.amzn2.0.1.aarch64
mono-data-6.12.0-5.amzn2.0.1.aarch64
mono-data-sqlite-6.12.0-5.amzn2.0.1.aarch64
mono-data-oracle-6.12.0-5.amzn2.0.1.aarch64
ibm-data-db2-6.12.0-5.amzn2.0.1.aarch64
monodoc-6.12.0-5.amzn2.0.1.aarch64
monodoc-devel-6.12.0-5.amzn2.0.1.aarch64
mono-complete-6.12.0-5.amzn2.0.1.aarch64
mono-debuginfo-6.12.0-5.amzn2.0.1.aarch64
i686:
mono-core-6.12.0-5.amzn2.0.1.i686
mono-winfx-6.12.0-5.amzn2.0.1.i686
mono-mvc-6.12.0-5.amzn2.0.1.i686
mono-mvc-devel-6.12.0-5.amzn2.0.1.i686
mono-devel-6.12.0-5.amzn2.0.1.i686
mono-locale-extras-6.12.0-5.amzn2.0.1.i686
mono-extras-6.12.0-5.amzn2.0.1.i686
mono-reactive-6.12.0-5.amzn2.0.1.i686
mono-reactive-winforms-6.12.0-5.amzn2.0.1.i686
mono-reactive-devel-6.12.0-5.amzn2.0.1.i686
mono-winforms-6.12.0-5.amzn2.0.1.i686
mono-wcf-6.12.0-5.amzn2.0.1.i686
mono-web-6.12.0-5.amzn2.0.1.i686
mono-web-devel-6.12.0-5.amzn2.0.1.i686
mono-data-6.12.0-5.amzn2.0.1.i686
mono-data-sqlite-6.12.0-5.amzn2.0.1.i686
mono-data-oracle-6.12.0-5.amzn2.0.1.i686
ibm-data-db2-6.12.0-5.amzn2.0.1.i686
monodoc-6.12.0-5.amzn2.0.1.i686
monodoc-devel-6.12.0-5.amzn2.0.1.i686
mono-complete-6.12.0-5.amzn2.0.1.i686
mono-debuginfo-6.12.0-5.amzn2.0.1.i686
src:
mono-6.12.0-5.amzn2.0.1.src
x86_64:
mono-core-6.12.0-5.amzn2.0.1.x86_64
mono-winfx-6.12.0-5.amzn2.0.1.x86_64
mono-mvc-6.12.0-5.amzn2.0.1.x86_64
mono-mvc-devel-6.12.0-5.amzn2.0.1.x86_64
mono-devel-6.12.0-5.amzn2.0.1.x86_64
mono-locale-extras-6.12.0-5.amzn2.0.1.x86_64
mono-extras-6.12.0-5.amzn2.0.1.x86_64
mono-reactive-6.12.0-5.amzn2.0.1.x86_64
mono-reactive-winforms-6.12.0-5.amzn2.0.1.x86_64
mono-reactive-devel-6.12.0-5.amzn2.0.1.x86_64
mono-winforms-6.12.0-5.amzn2.0.1.x86_64
mono-wcf-6.12.0-5.amzn2.0.1.x86_64
mono-web-6.12.0-5.amzn2.0.1.x86_64
mono-web-devel-6.12.0-5.amzn2.0.1.x86_64
mono-data-6.12.0-5.amzn2.0.1.x86_64
mono-data-sqlite-6.12.0-5.amzn2.0.1.x86_64
mono-data-oracle-6.12.0-5.amzn2.0.1.x86_64
ibm-data-db2-6.12.0-5.amzn2.0.1.x86_64
monodoc-6.12.0-5.amzn2.0.1.x86_64
monodoc-devel-6.12.0-5.amzn2.0.1.x86_64
mono-complete-6.12.0-5.amzn2.0.1.x86_64
mono-debuginfo-6.12.0-5.amzn2.0.1.x86_64