USN-5820-1: exuberant-ctags vulnerability

Publication date

24 January 2023

Overview

Exuberant ctags could be make to perform arbitary command execution if run with maliciously crafted user input


Packages

Details

Lorenz Hipp discovered a flaw in exuberant-ctags handling of the tag
filename command-line argument. A crafted tag filename specified
in the command line or in the configuration file could result in
arbitrary command execution.

Lorenz Hipp discovered a flaw in exuberant-ctags handling of the tag
filename command-line argument. A crafted tag filename specified
in the command line or in the configuration file could result in
arbitrary command execution.

Update instructions

In general, a standard system update will make all the necessary changes.

Learn more about how to get the fixes.

The problem can be corrected by updating your system to the following package versions:

Ubuntu Release Package Version
22.10 kinetic exuberant-ctags –  1:5.9~svn20110310-16ubuntu0.22.10.1
22.04 jammy exuberant-ctags –  1:5.9~svn20110310-16ubuntu0.22.04.1
20.04 focal exuberant-ctags –  1:5.9~svn20110310-12ubuntu0.1
18.04 bionic exuberant-ctags –  1:5.9~svn20110310-11ubuntu0.1
16.04 xenial exuberant-ctags –  1:5.9~svn20110310-11ubuntu0.1~esm1  

Reduce your security exposure

Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.


Have additional questions?

Talk to a member of the team ›