Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 507
Alerts This Week
Warning Icon 1 507

Debian: 752-4 Urgent: Unzip Memory Leak and Denial of Service Risks

debian
Calendar Grey January 21, 2005
Scroller Debian
- --------------------------------------------------------------------------Debian Security Advisory
Several vulnerabilities have been discovered in unarj, a non-free ARJ unarchive utility.

Summary


A buffer overflow has been discovered when handling long file
names contained in an archive. An attacker could create a
specially crafted archive which could cause unarj to crash or
possibly execute arbitrary code when being extracted by a victim.

CAN-2004-1027

A directory traversal vulnerability has been found so that an
attacker could create a specially crafted archive which would
create files in the parent directory when being extracted by a
victim. When used recursively, this vulnerability could be used
to overwrite critical system files and programs.

For the stable distribution (woody) these problems have been fixed in
version 2.43-3woody1.

For the unstable distribution (sid) these problems don't apply since
unstable/non-free does not contain the unarj package.

We recommend that you upgrade your unarj package.


Upgrade Instructions
- --------------------wget url
will fetch the file for you
dpkg -i file.deb
will instal...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.