Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

Debian: 752-4 Urgent: Unzip Memory Leak and Denial of Service Risks

debian
Calendar Grey January 21, 2005
Debian Logo
Multiple weaknesses found in unarj. It is advised to implement updates to address significant security concerns.
Several vulnerabilities have been discovered in unarj, a non-free ARJ unarchive utility.

Summary


A buffer overflow has been discovered when handling long file
names contained in an archive. An attacker could create a
specially crafted archive which could cause unarj to crash or
possibly execute arbitrary code when being extracted by a victim.

CAN-2004-1027

A directory traversal vulnerability has been found so that an
attacker could create a specially crafted archive which would
create files in the parent directory when being extracted by a
victim. When used recursively, this vulnerability could be used
to overwrite critical system files and programs.

For the stable distribution (woody) these problems have been fixed in
version 2.43-3woody1.

For the unstable distribution (sid) these problems don't apply since
unstable/non-free does not contain the unarj package.

We recommend that you upgrade your unarj package.


Upgrade Instructions
- --------------------wget url
will fetch the file for you
dpkg -i file.deb
will instal...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here