Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2016:1029-1

Опубликовано: 13 апр. 2016
Источник: suse-cvrf

Описание

Security update for lhasa

This update for lhasa to 0.3.1 fixes the following issues:

These security issues were fixed:

  • CVE-2016-2347: Integer underflow vulnerability in the code for doing LZH level 3 header decodes (boo#973790)[

These non-security issues were fixed:

  • PMarc -pm1- archives that contain truncated compressed data (the decompressed length is longer than what can be read from the compressed data) now decompress as intended. Certain archives in the wild make the assumption that this can be done.
  • LArc -lz5- archives that make use of the initial history buffer now decompress correctly.
  • The tests no longer use predictable temporary paths.

Список пакетов

openSUSE Leap 42.1
lhasa-0.3.1-10.1
lhasa-devel-0.3.1-10.1
liblhasa0-0.3.1-10.1

Описание

Integer underflow in the decode_level3_header function in lib/lha_file_header.c in Lhasa before 0.3.1 allows remote attackers to execute arbitrary code via a crafted archive.


Затронутые продукты
openSUSE Leap 42.1:lhasa-0.3.1-10.1
openSUSE Leap 42.1:lhasa-devel-0.3.1-10.1
openSUSE Leap 42.1:liblhasa0-0.3.1-10.1

Ссылки