A buffer overflow in xdelta might allow remote attackers to execute arbitrary code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201701-40 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: xdelta: User-assisted execution of arbitrary code Date: January 17, 2017 Bugs: #574408 ID: 201701-40 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= A buffer overflow in xdelta might allow remote attackers to execute arbitrary code. Background ========= Xdelta is a C library and command-line tool for delta compression using VCDIFF/RFC 3284 streams. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 dev-util/xdelta < 3.0.10 > = 3.0.10 Description ========== A buffer overflow can be triggered within xdelta when ran against a malicious input file. Impact ===== A remote attacker could coerce the victim to run xdelta against a malicious input file. This may be leveraged by an attacker to crash xdelta and gain control of program execution. Workaround ========= There is no known workaround at this time. Resolution ========= All xdelta users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =dev-util/xdelta-3.0.10" References ========= [ 1 ] CVE-2014-9765 https://www.cve.org/CVERecord?id=CVE-2014-9765 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201701-40 Concerns? ======== Security is a primaryfocus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
xdelta shipped with FC4 isn't compiled with large file support and uses obsolete glib-1.2 library. The libedsio symbols are missing from the installed libxdelta library. This release introduces xdelta ported to glib-2 and fixes the noted issues.. ---------------------------------------------------------------------Fedora Update Notification FEDORA-2005-876 2005-09-12 ---------------------------------------------------------------------Product : Fedora Core 4 Name : xdelta Version : 1.1.3 Release : 17.fc4 Summary : A binary file delta generator and an RCS replacement library. Description : Xdelta (X for XCF: the eXperimental Computing Facility at Berkeley) is a binary delta generator (like a diff program for binaries) and an RCS version control replacement library. The Xdelta library performs its work independently of the actual format used to encode the file and is intended to be used by various higher-level programs such as XCF's Project Revision Control System (PRCS). PRCS is a front end for a version control toolset. Xdelta uses a binary file delta algorithm to replace the standard diff program used by RCS. ---------------------------------------------------------------------Update Information: xdelta shipped with FC4 isn't compiled with large file support and uses obsolete glib-1.2 library. The libedsio symbols are missing from the installed libxdelta library. This release introduces xdelta ported to glib-2 and fixes the noted issues. ---------------------------------------------------------------------* Mon Sep 12 2005 Jindrich Novy 1.1.3-17.fc4 - link libxdelta against libedsio (#165978) - add support for large files (#155524) - port to use glib2 instead of obsolete glib1.2 (#136221) - convert spec to UTF-8 ---------------------------------------------------------------------This update can be downloaded from: 3a94b7bd642960731f6e38d7d4b5d05f SRPMS/xdelta-1.1.3-17.fc4.src.rpm 9306247120f496282ebb9f42bed3a069 ppc/xdelta-1.1.3-17.fc4.ppc.rpm 08ca1c6f1216955556405c35ec879743 ppc/xdelta-devel-1.1.3-17.fc4.ppc.rpm c00e6bc5915c87caae03555f3613ed55 ppc/debug/xdelta-debuginfo-1.1.3-17.fc4.ppc.rpm 48c7d5107da7dbc2ac6f690ac7f1243c x86_64/xdelta-1.1.3-17.fc4.x86_64.rpm 4b80e426540aa645644965eb17878e48 x86_64/xdelta-devel-1.1.3-17.fc4.x86_64.rpm 931c1025795e9086fea8f55fa5f569ce x86_64/debug/xdelta-debuginfo-1.1.3-17.fc4.x86_64.rpm 2a8a7a78139b5d88988536099a6bad3a i386/xdelta-1.1.3-17.fc4.i386.rpm 0b895d6b960689c02711100dc1df2e19 i386/xdelta-devel-1.1.3-17.fc4.i386.rpm acef04ad4519a2ceb57a992289442f9b i386/debug/xdelta-debuginfo-1.1.3-17.fc4.i386.rpm This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date' command. ----------------------------------------------------------------------- fedora-announce-list mailing list
Get the latest Linux and open source security news straight to your inbox.