Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 544
Alerts This Week
Warning Icon 1 544

SUSE: 2018:1883-1 Moderate: Unzip Denial of Service and Buffer Overflow

suse
Calendar Grey July 5, 2018
Scroller Suse
SUSE Releases Patch for Unzip Mitigating Two Vulnerabilities Rated as Moderate Severity, Includes Detailed Guidelines.
An update that solves two vulnerabilities and has one errata is now available

Summary

This update for unzip fixes the following issues: - CVE-2014-9636: Prevent denial of service (out-of-bounds read or write and crash) via an extra field with an uncompressed size smaller than the compressed field size in a zip archive that advertises STORED method compression (bsc#914442) - CVE-2018-1000035: Prevent heap-based buffer overflow in the processing of password-protected archives that allowed an attacker to perform a denial of service or to possibly achieve code execution (bsc#1080074) This non-security issue was fixed: +- Allow processing of Windows zip64 archives (Windows archivers set total_disks field to 0 but per standard, valid values are 1 and higher) (bnc#910683) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods

References

#1080074 #910683 #914442

Cross- CVE-2014-9636 CVE-2018-1000035

Affected Products:

SUSE Linux Enterprise Module for Basesystem 15

https://www.suse.com/security/cve/CVE-2014-9636.html

https://www.suse.com/security/cve/CVE-2018-1000035.html

https://bugzilla.suse.com/1080074

https://bugzilla.suse.com/910683

https://bugzilla.suse.com/914442

Announcement ID: SUSE-SU-2018:1883-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.