Описание
Security update for libmspack
libmspack was updated to fix security issues.
These security issues were fixed:
- CVE-2014-9732: The cabd_extract function in cabd.c in libmspack did not properly maintain decompression callbacks in certain cases where an invalid file follows a valid file, which allowed remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted CAB archive (bnc#934524).
- CVE-2015-4467: The chmd_init_decomp function in chmd.c in libmspack did not properly validate the reset interval, which allowed remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted CHM file (bnc#934525).
- CVE-2015-4468: Multiple integer overflows in the search_chunk function in chmd.c in libmspack allowed remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted CHM file (bnc#934526).
- CVE-2015-4469: The chmd_read_headers function in chmd.c in libmspack did not validate name lengths, which allowed remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted CHM file (bnc#934526).
- CVE-2015-4470: Off-by-one error in the inflate function in mszipd.c in libmspack allowed remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted CAB archive (bnc#934527).
- CVE-2015-4471: Off-by-one error in the lzxd_decompress function in lzxd.c in libmspack allowed remote attackers to cause a denial of service (buffer under-read and application crash) via a crafted CAB archive (bnc#934528).
- CVE-2015-4472: Off-by-one error in the READ_ENCINT macro in chmd.c in libmspack allowed remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted CHM file (bnc#934529).
Список пакетов
SUSE Linux Enterprise Desktop 12
SUSE Linux Enterprise Desktop 12 SP1
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server 12 SP1
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server for SAP Applications 12 SP1
SUSE Linux Enterprise Software Development Kit 12
SUSE Linux Enterprise Software Development Kit 12 SP1
Ссылки
- Link for SUSE-SU-2016:0011-1
- E-Mail link for SUSE-SU-2016:0011-1
- SUSE Security Ratings
- SUSE Bug 934524
- SUSE Bug 934525
- SUSE Bug 934526
- SUSE Bug 934527
- SUSE Bug 934528
- SUSE Bug 934529
- SUSE CVE CVE-2014-9732 page
- SUSE CVE CVE-2015-4467 page
- SUSE CVE CVE-2015-4468 page
- SUSE CVE CVE-2015-4469 page
- SUSE CVE CVE-2015-4470 page
- SUSE CVE CVE-2015-4471 page
- SUSE CVE CVE-2015-4472 page
Описание
The cabd_extract function in cabd.c in libmspack before 0.5 does not properly maintain decompression callbacks in certain cases where an invalid file follows a valid file, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted CAB archive.
Затронутые продукты
Ссылки
- CVE-2014-9732
- SUSE Bug 934524
- SUSE Bug 934533
Описание
The chmd_init_decomp function in chmd.c in libmspack before 0.5 does not properly validate the reset interval, which allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted CHM file.
Затронутые продукты
Ссылки
- CVE-2015-4467
- SUSE Bug 934524
- SUSE Bug 934525
- SUSE Bug 934529
- SUSE Bug 934533
Описание
Multiple integer overflows in the search_chunk function in chmd.c in libmspack before 0.5 allow remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted CHM file.
Затронутые продукты
Ссылки
- CVE-2015-4468
- SUSE Bug 934524
- SUSE Bug 934526
- SUSE Bug 934529
- SUSE Bug 934533
Описание
The chmd_read_headers function in chmd.c in libmspack before 0.5 does not validate name lengths, which allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted CHM file.
Затронутые продукты
Ссылки
- CVE-2015-4469
- SUSE Bug 934524
- SUSE Bug 934526
- SUSE Bug 934529
- SUSE Bug 934533
Описание
Off-by-one error in the inflate function in mszipd.c in libmspack before 0.5 allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted CAB archive.
Затронутые продукты
Ссылки
- CVE-2015-4470
- SUSE Bug 934527
- SUSE Bug 934533
Описание
Off-by-one error in the lzxd_decompress function in lzxd.c in libmspack before 0.5 allows remote attackers to cause a denial of service (buffer under-read and application crash) via a crafted CAB archive.
Затронутые продукты
Ссылки
- CVE-2015-4471
- SUSE Bug 934528
- SUSE Bug 934533
Описание
Off-by-one error in the READ_ENCINT macro in chmd.c in libmspack before 0.5 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted CHM file.
Затронутые продукты
Ссылки
- CVE-2015-4472
- SUSE Bug 934525
- SUSE Bug 934529
- SUSE Bug 934533