Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Mageia 8: MGASA-2023-0107 Moderate: Unarj Remote Code Execution

mageia
Calendar Grey March 24, 2023
Dist Mageia Esm H88
Revised unarj software addresses vulnerabilities related to memory corruption and unintended file replacements. Security updates released on March 24, 2023.
Buffer overflow in unarj before 2.63a-r2 allows remote attackers to execute arbitrary code via an arj archive that contains long filenames

Summary

Buffer overflow in unarj before 2.63a-r2 allows remote attackers to execute arbitrary code via an arj archive that contains long filenames. (CVE-2004-0947) Directory traversal vulnerability in the -x (extract) command line option in unarj allows remote attackers to overwrite arbitrary files via an arj archive with filenames that contain .. (dot dot) sequences. (CVE-2004-1027)

References

- https://bugs.mageia.org/show_bug.cgi?id=31546

- https://www.cve.org/CVERecord?id=CVE-2004-0947

- https://www.cve.org/CVERecord?id=CVE-2004-1027

Resolution

SRPMS

- 8/tainted/unarj-2.65-6.1.mga8.tainted

Publication date: 24 Mar 2023
URL: https://advisories.mageia.org/MGASA-2023-0107.html
Type: security
CVE: CVE-2004-0947, CVE-2004-1027

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here