Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2015:0377-1

Опубликовано: 20 фев. 2015
Источник: suse-cvrf

Описание

Security update for unzip

This update fixes the following security issues:

* CVE-2014-8139: input sanitization errors (bnc#909214) * CVE-2014-9636: out-of-bounds read/write in test_compr_eb() (bnc#914442)

Security Issues:

* CVE-2014-9636 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9636> * CVE-2014-8139 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8139>

Список пакетов

SUSE Linux Enterprise Desktop 11 SP3
unzip-6.00-11.13.1
SUSE Linux Enterprise Server 11 SP3
unzip-6.00-11.13.1
SUSE Linux Enterprise Server 11 SP3-TERADATA
unzip-6.00-11.13.1
SUSE Linux Enterprise Server for SAP Applications 11 SP3
unzip-6.00-11.13.1

Описание

Heap-based buffer overflow in the CRC32 verification in Info-ZIP UnZip 6.0 and earlier allows remote attackers to execute arbitrary code via a crafted zip file in the -t command argument to the unzip command.


Затронутые продукты
SUSE Linux Enterprise Desktop 11 SP3:unzip-6.00-11.13.1
SUSE Linux Enterprise Server 11 SP3-TERADATA:unzip-6.00-11.13.1
SUSE Linux Enterprise Server 11 SP3:unzip-6.00-11.13.1
SUSE Linux Enterprise Server for SAP Applications 11 SP3:unzip-6.00-11.13.1

Ссылки

Описание

Heap-based buffer overflow in the test_compr_eb function in Info-ZIP UnZip 6.0 and earlier allows remote attackers to execute arbitrary code via a crafted zip file in the -t command argument to the unzip command.


Затронутые продукты
SUSE Linux Enterprise Desktop 11 SP3:unzip-6.00-11.13.1
SUSE Linux Enterprise Server 11 SP3-TERADATA:unzip-6.00-11.13.1
SUSE Linux Enterprise Server 11 SP3:unzip-6.00-11.13.1
SUSE Linux Enterprise Server for SAP Applications 11 SP3:unzip-6.00-11.13.1

Ссылки

Описание

Heap-based buffer overflow in the getZip64Data function in Info-ZIP UnZip 6.0 and earlier allows remote attackers to execute arbitrary code via a crafted zip file in the -t command argument to the unzip command.


Затронутые продукты
SUSE Linux Enterprise Desktop 11 SP3:unzip-6.00-11.13.1
SUSE Linux Enterprise Server 11 SP3-TERADATA:unzip-6.00-11.13.1
SUSE Linux Enterprise Server 11 SP3:unzip-6.00-11.13.1
SUSE Linux Enterprise Server for SAP Applications 11 SP3:unzip-6.00-11.13.1

Ссылки

Описание

unzip 6.0 allows remote attackers to cause a denial of service (out-of-bounds read or write and crash) via an extra field with an uncompressed size smaller than the compressed field size in a zip archive that advertises STORED method compression.


Затронутые продукты
SUSE Linux Enterprise Desktop 11 SP3:unzip-6.00-11.13.1
SUSE Linux Enterprise Server 11 SP3-TERADATA:unzip-6.00-11.13.1
SUSE Linux Enterprise Server 11 SP3:unzip-6.00-11.13.1
SUSE Linux Enterprise Server for SAP Applications 11 SP3:unzip-6.00-11.13.1

Ссылки