It was discovered that XZ Utils did not properly manage memory when attempting to append data to a decoded index that contained no records. An attacker could possibly use this issue to cause XZ Utils to crash, resulting in a denial of service, or execute arbitrary code.
5.2.5-2ubuntu1.15.6.1+really5.4.5-1ubuntu0.35.8.1-1ubuntu0.15.1.1alpha+20120614-2ubuntu2.14.04.1+esm25.1.1alpha+20120614-2ubuntu2.16.04.1+esm25.2.2-1.3ubuntu0.1+esm15.2.4-1ubuntu1.1+esm1