Harri K. Koskinen discovered a flaw in the multithreaded .xz decoder lzma_stream_decoder_mt in xz-utils, the XZ-format compression utilities, which may lead to denial of service (application crash) or the execution of arbitrary code.
https://security-tracker.debian.org/tracker/DSA-5895-1
Continue reading...
https://security-tracker.debian.org/tracker/DSA-5895-1
Continue reading...

