Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 521
Alerts This Week
Warning Icon 1 521

Debian 0.7.11a-3 Critical: unADF Buffer Overflow and Code Execution

debian
Calendar Grey September 24, 2016
Scroller Debian
Debian Security Advisory DSA-3677-1 addresses issues found in libXYZ which affect system integrity and data management.
Tuomas Räsänen discovered two vulnerabilities in unADF, a tool to extract files from an Amiga Disk File dump (.adf): CVE-2016-1243

Summary

CVE-2016-1243

A stack buffer overflow in the function extractTree() might allow an
attacker, with control on the content of a ADF file, to execute
arbitrary code with the privileges of the program execution.

CVE-2016-1244

The unADF extractor creates the path in the destination via a mkdir
in a system() call. Since there was no sanitization on the input of
the filenames, an attacker can directly inject code in the pathnames
of archived directories in an ADF file.

For the oldstable distribution (wheezy), these problems have been fixed
in version 0.7.11a-3+deb7u1.

For the stable distribution (jessie), these problems have been fixed in
version 0.7.11a-3+deb8u1.

For the unstable distribution (sid), these problems have been fixed in
version 0.7.11a-4.

We recommend that you upgrade your unadf packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/



Severity
critical
Lowest
Low
Medium
High
Critical

Package: unadf
CVE ID: CVE-2016-1243 CVE-2016-1244

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.