It was reported that unrar fixed a VMSF_DELTA memory corruption issue in their latest version unrarsrc-5.5.5.tar.gz. This problem was reported to Sophos AV in 2012 but never reach upstream rar. . Package : unrar-nonfree Version : 1:4.1.4-1+deb7u2 CVE ID : CVE-2012-6706 Debian Bug : #865461 It was reported that unrar fixed a VMSF_DELTA memory corruption issue in their latest version unrarsrc-5.5.5.tar.gz. This problem was reported to Sophos AV in 2012 but never reach upstream rar. For Debian 7 "Wheezy", these problems have been fixed in version 1:4.1.4-1+deb7u2. We recommend that you upgrade your unrar-nonfree packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Enhance the unrar-nonfree software on Debian 7 to resolve a memory corruption vulnerability corrected in release 1:4.1.4-1+deb7u2.. Debian LTS, unrar-nonfree, memory issue, security update, software upgrade. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.