Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2017:1658-1

Опубликовано: 22 июн. 2017
Источник: suse-cvrf

Описание

Security update for unrar

This update for unrar to version 5.5 fixes the following issues:

Version 5.5.5

Version 5.5.1

  • Based on RAR 5.50 beta1
  • Added extraction support for .LZ archives created by Lzip compressor.
  • Modern TAR tools can store high precision file times, lengthy file names and large file sizes in special PAX extended headers inside of TAR archive. Now WinRAR supports such PAX headers and uses them when extracting TAR archives.
  • unrar no longer fails to unpack files in ZIP archives compressed with XZ algorithm and encrypted with AES

Version 5.4.5.

  • Based on final RAR 5.40.
  • If RAR recovery volumes (.rev files) are present in the same folder as usual RAR volumes, archive test command verifies .rev contents after completing testing .rar files. If you wish to test only .rev files without checking .rar volumes, you can run: unrar t arcname.part1.rev.
  • If -p switch is used without optional parameter, a password can be also set with file redirection or pipe.
  • unrar treats 'arcname.partN' as 'arcname.partN.rar' if 'arcname.partN' does not exist and 'arcname.part#.rar' exists. For example, it is allowed to run: unrar x arcname.part01 to start extraction from 'arcname.part01.rar'.

Список пакетов

openSUSE Leap 42.2 NonFree
libunrar-devel-5.5.5-3.1
libunrar5_5_5-5.5.5-3.1
unrar-5.5.5-3.1

Описание

A VMSF_DELTA memory corruption was discovered in unrar before 5.5.5, as used in Sophos Anti-Virus Threat Detection Engine before 3.37.2 and other products, that can lead to arbitrary code execution. An integer overflow can be caused in DataSize+CurChannel. The result is a negative value of the "DestPos" variable, which allows the attacker to write out of bounds when setting Mem[DestPos].


Затронутые продукты
openSUSE Leap 42.2 NonFree:libunrar-devel-5.5.5-3.1
openSUSE Leap 42.2 NonFree:libunrar5_5_5-5.5.5-3.1
openSUSE Leap 42.2 NonFree:unrar-5.5.5-3.1

Ссылки