USN-6745-1: Percona XtraBackup vulnerability
22 April 2024
percona-xtrabackup could be made to run programs as your login if it opened a specially crafted file.
Releases
Packages
- percona-xtrabackup - Open source backup tool for InnoDB and XtraDB
Details
It was discovered that in Percona XtraBackup, a local crafted filename
could trigger arbitrary code execution.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 18.04
-
percona-xtrabackup
-
2.4.9-0ubuntu2+esm1
Available with Ubuntu Pro
Ubuntu 16.04
-
percona-xtrabackup
-
2.3.7-0ubuntu0.16.04.2+esm1
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.