Synopsis
Important: plexus-archiver security update
Type/Severity
Security Advisory: Important
Red Hat Insights patch analysis
Identify and remediate systems affected by this advisory.
View affected systems
Topic
An update for plexus-archiver is now available for Red Hat Enterprise Linux 7.
Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.
Description
The Plexus project provides a full software stack for creating and executing software projects. Based on the Plexus container, the applications can utilise component-oriented programming to build modular, reusable components that can easily be assembled and reused. The plexus-archiver component provides functions to create and extract archives.
Security Fix(es):
- plexus-archiver: Arbitrary File Creation in AbstractUnArchiver (CVE-2023-37460)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Products
-
Red Hat Enterprise Linux Server 7 x86_64
-
Red Hat Enterprise Linux Server - Extended Life Cycle Support 7 x86_64
-
Red Hat Enterprise Linux Workstation 7 x86_64
-
Red Hat Enterprise Linux Desktop 7 x86_64
-
Red Hat Enterprise Linux for IBM z Systems 7 s390x
-
Red Hat Enterprise Linux for Power, big endian 7 ppc64
-
Red Hat Enterprise Linux for Scientific Computing 7 x86_64
-
Red Hat Enterprise Linux for Power, little endian 7 ppc64le
-
Red Hat Enterprise Linux Server - Extended Life Cycle Support (for IBM z Systems) 7 s390x
-
Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, big endian 7 ppc64
-
Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, little endian 7 ppc64le
Fixes
-
BZ - 2242288
- CVE-2023-37460 plexus-archiver: Arbitrary File Creation in AbstractUnArchiver
Note:
More recent versions of these packages may be available.
Click a package name for more details.
Red Hat Enterprise Linux Server 7
SRPM |
plexus-archiver-2.4.2-6.el7_9.src.rpm
|
SHA-256: be8ad81f27181d856388db2db56946d6f23a844164b6e0fd1b6889ddb8cebae0 |
x86_64 |
plexus-archiver-2.4.2-6.el7_9.noarch.rpm
|
SHA-256: 2d8054ceedaed067a02bfdfd6787ccfe87345117fecbbfcc29364c74fd6b827b |
plexus-archiver-javadoc-2.4.2-6.el7_9.noarch.rpm
|
SHA-256: 216f8882e5945e1b9edbc9986f1aab669d2671efb277194b38a1f25b425230e8 |
Red Hat Enterprise Linux Server - Extended Life Cycle Support 7
SRPM |
plexus-archiver-2.4.2-6.el7_9.src.rpm
|
SHA-256: be8ad81f27181d856388db2db56946d6f23a844164b6e0fd1b6889ddb8cebae0 |
x86_64 |
plexus-archiver-2.4.2-6.el7_9.noarch.rpm
|
SHA-256: 2d8054ceedaed067a02bfdfd6787ccfe87345117fecbbfcc29364c74fd6b827b |
plexus-archiver-javadoc-2.4.2-6.el7_9.noarch.rpm
|
SHA-256: 216f8882e5945e1b9edbc9986f1aab669d2671efb277194b38a1f25b425230e8 |
Red Hat Enterprise Linux Workstation 7
SRPM |
plexus-archiver-2.4.2-6.el7_9.src.rpm
|
SHA-256: be8ad81f27181d856388db2db56946d6f23a844164b6e0fd1b6889ddb8cebae0 |
x86_64 |
plexus-archiver-2.4.2-6.el7_9.noarch.rpm
|
SHA-256: 2d8054ceedaed067a02bfdfd6787ccfe87345117fecbbfcc29364c74fd6b827b |
plexus-archiver-javadoc-2.4.2-6.el7_9.noarch.rpm
|
SHA-256: 216f8882e5945e1b9edbc9986f1aab669d2671efb277194b38a1f25b425230e8 |
Red Hat Enterprise Linux Desktop 7
SRPM |
plexus-archiver-2.4.2-6.el7_9.src.rpm
|
SHA-256: be8ad81f27181d856388db2db56946d6f23a844164b6e0fd1b6889ddb8cebae0 |
x86_64 |
plexus-archiver-2.4.2-6.el7_9.noarch.rpm
|
SHA-256: 2d8054ceedaed067a02bfdfd6787ccfe87345117fecbbfcc29364c74fd6b827b |
plexus-archiver-javadoc-2.4.2-6.el7_9.noarch.rpm
|
SHA-256: 216f8882e5945e1b9edbc9986f1aab669d2671efb277194b38a1f25b425230e8 |
Red Hat Enterprise Linux for IBM z Systems 7
SRPM |
plexus-archiver-2.4.2-6.el7_9.src.rpm
|
SHA-256: be8ad81f27181d856388db2db56946d6f23a844164b6e0fd1b6889ddb8cebae0 |
s390x |
plexus-archiver-2.4.2-6.el7_9.noarch.rpm
|
SHA-256: 2d8054ceedaed067a02bfdfd6787ccfe87345117fecbbfcc29364c74fd6b827b |
plexus-archiver-javadoc-2.4.2-6.el7_9.noarch.rpm
|
SHA-256: 216f8882e5945e1b9edbc9986f1aab669d2671efb277194b38a1f25b425230e8 |
Red Hat Enterprise Linux for Power, big endian 7
SRPM |
plexus-archiver-2.4.2-6.el7_9.src.rpm
|
SHA-256: be8ad81f27181d856388db2db56946d6f23a844164b6e0fd1b6889ddb8cebae0 |
ppc64 |
plexus-archiver-2.4.2-6.el7_9.noarch.rpm
|
SHA-256: 2d8054ceedaed067a02bfdfd6787ccfe87345117fecbbfcc29364c74fd6b827b |
plexus-archiver-javadoc-2.4.2-6.el7_9.noarch.rpm
|
SHA-256: 216f8882e5945e1b9edbc9986f1aab669d2671efb277194b38a1f25b425230e8 |
Red Hat Enterprise Linux for Scientific Computing 7
SRPM |
plexus-archiver-2.4.2-6.el7_9.src.rpm
|
SHA-256: be8ad81f27181d856388db2db56946d6f23a844164b6e0fd1b6889ddb8cebae0 |
x86_64 |
plexus-archiver-2.4.2-6.el7_9.noarch.rpm
|
SHA-256: 2d8054ceedaed067a02bfdfd6787ccfe87345117fecbbfcc29364c74fd6b827b |
plexus-archiver-javadoc-2.4.2-6.el7_9.noarch.rpm
|
SHA-256: 216f8882e5945e1b9edbc9986f1aab669d2671efb277194b38a1f25b425230e8 |
Red Hat Enterprise Linux for Power, little endian 7
SRPM |
plexus-archiver-2.4.2-6.el7_9.src.rpm
|
SHA-256: be8ad81f27181d856388db2db56946d6f23a844164b6e0fd1b6889ddb8cebae0 |
ppc64le |
plexus-archiver-2.4.2-6.el7_9.noarch.rpm
|
SHA-256: 2d8054ceedaed067a02bfdfd6787ccfe87345117fecbbfcc29364c74fd6b827b |
plexus-archiver-javadoc-2.4.2-6.el7_9.noarch.rpm
|
SHA-256: 216f8882e5945e1b9edbc9986f1aab669d2671efb277194b38a1f25b425230e8 |
Red Hat Enterprise Linux Server - Extended Life Cycle Support (for IBM z Systems) 7
SRPM |
plexus-archiver-2.4.2-6.el7_9.src.rpm
|
SHA-256: be8ad81f27181d856388db2db56946d6f23a844164b6e0fd1b6889ddb8cebae0 |
s390x |
plexus-archiver-2.4.2-6.el7_9.noarch.rpm
|
SHA-256: 2d8054ceedaed067a02bfdfd6787ccfe87345117fecbbfcc29364c74fd6b827b |
plexus-archiver-javadoc-2.4.2-6.el7_9.noarch.rpm
|
SHA-256: 216f8882e5945e1b9edbc9986f1aab669d2671efb277194b38a1f25b425230e8 |
Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, big endian 7
SRPM |
plexus-archiver-2.4.2-6.el7_9.src.rpm
|
SHA-256: be8ad81f27181d856388db2db56946d6f23a844164b6e0fd1b6889ddb8cebae0 |
ppc64 |
plexus-archiver-2.4.2-6.el7_9.noarch.rpm
|
SHA-256: 2d8054ceedaed067a02bfdfd6787ccfe87345117fecbbfcc29364c74fd6b827b |
plexus-archiver-javadoc-2.4.2-6.el7_9.noarch.rpm
|
SHA-256: 216f8882e5945e1b9edbc9986f1aab669d2671efb277194b38a1f25b425230e8 |
Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, little endian 7
SRPM |
plexus-archiver-2.4.2-6.el7_9.src.rpm
|
SHA-256: be8ad81f27181d856388db2db56946d6f23a844164b6e0fd1b6889ddb8cebae0 |
ppc64le |
plexus-archiver-2.4.2-6.el7_9.noarch.rpm
|
SHA-256: 2d8054ceedaed067a02bfdfd6787ccfe87345117fecbbfcc29364c74fd6b827b |
plexus-archiver-javadoc-2.4.2-6.el7_9.noarch.rpm
|
SHA-256: 216f8882e5945e1b9edbc9986f1aab669d2671efb277194b38a1f25b425230e8 |