pdated apache-commons-compress packages fix security vulnerability: A resource consumption vulnerability was discovered in apache-commons- compress in the way NioZipEncoding encodes filenames. Applications that use Compress to create archives, with one of the filenames within the . MGASA-2020-0001 - Updated apache-commons-compress- packages fix security vulnerability Publication date: 05 Jan 2020 URL: https://advisories.mageia.org/MGASA-2020-0001.html Type: security Affected Mageia releases: 7 CVE: CVE-2019-12402 pdated apache-commons-compress packages fix security vulnerability: A resource consumption vulnerability was discovered in apache-commons- compress in the way NioZipEncoding encodes filenames. Applications that use Compress to create archives, with one of the filenames within the archive being controlled by the user, may be vulnerable to this flaw. A remote attacker could exploit this flaw to cause an infinite loop during the archive creation, thus leading to a denial of service (CVE-2019-12402). References: - https://bugs.mageia.org/show_bug.cgi?id=25365 - https://lists.fedoraproject.org/archives/list/
This release fixes a heap buffer overflow when processing a shar archive by unshar tool if the arhive contains overlong lines.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-8f4b3fa844 2018-03-06 17:17:51.856083 --------------------------------------------------------------------------------Name : sharutils Product : Fedora 27 Version : 4.15.2 Release : 8.fc27 URL : http://www.gnu.org/software/sharutils/ Summary : The GNU shar utilities for packaging and unpackaging shell archives Description : The sharutils package contains the GNU shar utilities, a set of tools for encoding and decoding packages of files (in binary or text format) in a special plain text format called shell archives (shar). This format can be sent through e-mail (which can be problematic for regular binary files). The shar utility supports a wide range of capabilities (compressing, uuencoding, splitting long files for multi-part mailings, providing check-sums), which make it very flexible at creating shar files. After the files have been sent, the unshar tool scans mail messages looking for shar files. Unshar automatically strips off mail headers and introductory text and then unpacks the shar files. --------------------------------------------------------------------------------Update Information: This release fixes a heap buffer overflow when processing a shar archive by unshar tool if the arhive contains overlong lines. --------------------------------------------------------------------------------References: [ 1 ] Bug #1548018 - sharutils: heap-buffer-overflow in find_archive in unshar.c https://bugzilla.redhat.com/show_bug.cgi?id=1548018 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade sharutils' at the command line. For more information, refer to the dnf documentationavailable at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
This release fixes a heap buffer overflow when processing a shar archive by unshar tool if the arhive contains overlong lines.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-8f4b3fa844 2018-03-06 17:17:51.856083 --------------------------------------------------------------------------------Name : sharutils Product : Fedora 27 Version : 4.15.2 Release : 8.fc27 URL : http://www.gnu.org/software/sharutils/ Summary : The GNU shar utilities for packaging and unpackaging shell archives Description : The sharutils package contains the GNU shar utilities, a set of tools for encoding and decoding packages of files (in binary or text format) in a special plain text format called shell archives (shar). This format can be sent through e-mail (which can be problematic for regular binary files). The shar utility supports a wide range of capabilities (compressing, uuencoding, splitting long files for multi-part mailings, providing check-sums), which make it very flexible at creating shar files. After the files have been sent, the unshar tool scans mail messages looking for shar files. Unshar automatically strips off mail headers and introductory text and then unpacks the shar files. --------------------------------------------------------------------------------Update Information: This release fixes a heap buffer overflow when processing a shar archive by unshar tool if the arhive contains overlong lines. --------------------------------------------------------------------------------References: [ 1 ] Bug #1548018 - sharutils: heap-buffer-overflow in find_archive in unshar.c https://bugzilla.redhat.com/show_bug.cgi?id=1548018 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade sharutils' at the command line. For more information, refer to the dnf documentationavailable at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.