Issues found running Lynis and Arch-Audit

Hello!
Not sure if I am putting this info in the right spot. Just want to help.

minizip is affected by arbitrary code execution. Critical risk!
grub is affected by multiple issues. High risk!
cpio is affected by arbitrary command execution. Medium risk!
giflib is affected by information disclosure. Medium risk!
libtiff is affected by unknown, denial of service. Medium risk!
linux-zen is affected by multiple issues. Medium risk!
openjpeg2 is affected by arbitrary code execution. Medium risk!
openssl is affected by arbitrary command execution. Medium risk!
openvpn is affected by information disclosure. Medium risk!
perl is affected by signature forgery, directory traversal. Medium risk!
wget is affected by information disclosure. Medium risk!
xdg-utils is affected by information disclosure. Medium risk!
lua52 is affected by denial of service. Low risk!
p7zip is affected by denial of service. Low risk!

:warning: Missing information requested in the template may result in not receiving assistance :warning:

Make sure you have done the following before you post:

Issue still unresolved? Then:

  • ONE issue per topic.
  • Describe your issue in detail. The more we know, the better we can help
  • Show us the results of your searches, and what you’ve tried
  • After rebooting, post the FULL output of garuda-inxi in the body of the post (not linked externally, or collapsed with the “hide details” feature)
  • Format terminal output (including your garuda-inxi) as a code block by clicking the preformatted text button (</>) , or put three tildes (~) above and below the text

The template above should be deleted before posting your help request.

There are often vulnerabilities without fixes available.

arch-audit -u will show you which packages are vulnerable and have a fix available.

That being said, many of those packages have been there for a long time now.

4 Likes

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.