Alerts This Week
Warning Icon 1 664
Alerts This Week
Warning Icon 1 664

Debian 8: DLA-2010-1 Critical: bsdiff Heap Overflow Risk

debian lts
Calendar Grey November 26, 2019
Dist Debian Esm H88
To fix integer signedness in bsdiff, validate inputs thoroughly before arithmetic to avoid unintended negative values and prevent buffer overflows.
An issue in bsdiff, a tool to generate/apply a patch between two binary files, has been found

Summary

Using a crafted patch file an integer signedness error in bspatch could be
used for a heap based buffer overflow and possibly execution of arbitrary
code.


For Debian 8 "Jessie", this problem has been fixed in version
4.3-15+deb8u1.

We recommend that you upgrade your bsdiff packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS



Severity
critical
Lowest
Low
Medium
High
Critical

Package: bsdiff
Version: 4.3-15+deb8u1
CVE ID: CVE-2014-9862

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here