security advisorycriticalcode execution
Marcin Noga discovered an integer underflow in Lhasa, a lzh archive decompressor, which might result in the execution of arbitrary code if a malformed archive is processed. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 - ------------------------------------------------------------------------- Debian Security Advisory DSA-3540-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff April 03, 2016 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : lhasa CVE ID : CVE-2016-2347 Marcin Noga discovered an integer underflow in Lhasa, a lzh archive decompressor, which might result in the execution of arbitrary code if a malformed archive is processed. For the oldstable distribution (wheezy), this problem has been fixed in version 0.0.7-2+deb7u1. For the stable distribution (jessie), this problem has been fixed in version 0.2.0+git3fe46-1+deb8u1. For the testing distribution (stretch), this problem has been fixed in version 0.3.1-1. For the unstable distribution (sid), this problem has been fixed in version 0.3.1-1. We recommend that you upgrade your lhasa packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Buffer overflow vulnerability in the Lhasa decompressor could permit remote code execution. Users of Ubuntu are advised to update their systems immediately.. Debian Security, Lhasa Update, Archive Decompressor, Integer Underflow, Security Patch. . Severity: Critical. LinuxSecurity.com Team
Apr 03, 2016
•Critical
Debian