bsdiff could be made to crash or run programs as your login if it opened a specially crafted file.. =========================================================================Ubuntu Security Notice USN-4500-1 September 15, 2020 bsdiff vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.04 LTS Summary: bsdiff could be made to crash or run programs as your login if it opened a specially crafted file. Software Description: - bsdiff: generate/apply a patch between two binary files Details: It was discovered that bsdiff mishandled certain input. If a user were tricked into opening a malicious file, an attacker could cause bsdiff to crash or potentially execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 LTS: bsdiff 4.3-15+deb8u1build0.16.04.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-4500-1 CVE-2014-9862 Package Information: https://launchpad.net/ubuntu/+source/bsdiff/4.3-15+deb8u1build0.16.04.1 -- ubuntu-security-announce mailing list
An issue in bsdiff, a tool to generate/apply a patch between two binary files, has been found. . Package : bsdiff Version : 4.3-15+deb8u1 CVE ID : CVE-2014-9862 An issue in bsdiff, a tool to generate/apply a patch between two binary files, has been found. Using a crafted patch file an integer signedness error in bspatch could be used for a heap based buffer overflow and possibly execution of arbitrary code. For Debian 8 "Jessie", this problem has been fixed in version 4.3-15+deb8u1. We recommend that you upgrade your bsdiff packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . To fix integer signedness in bsdiff, validate inputs thoroughly before arithmetic to avoid unintended negative values and prevent buffer overflows.. bsdiff security update, Debian LTS advisory, heap overflow prevention. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.