ALT-BU-2018-3552-1
Branch sisyphus update bulletin.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2018-8050
The af_get_page() function in lib/afflib_pages.cpp in AFFLIB (aka AFFLIBv3) through 3.7.16 allows remote attackers to cause a denial of service (segmentation fault) via a corrupt AFF image that triggers an unexpected pagesize value.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2016-9296
A null pointer dereference bug affects the 16.02 and many old versions of p7zip. A lack of null pointer check for the variable folders.PackPositions in function CInArchive::ReadAndDecodePackedStreams in CPP/7zip/Archive/7z/7zIn.cpp, as used in the 7z.so library and in 7z applications, will cause a crash and a denial of service when decoding malformed 7z files.
- 94294
- 94294
- https://github.com/yangke/7zip-null-pointer-dereference
- https://github.com/yangke/7zip-null-pointer-dereference
- https://sourceforge.net/p/p7zip/bugs/185/
- https://sourceforge.net/p/p7zip/bugs/185/
- https://sourceforge.net/p/p7zip/discussion/383043/thread/648d34db/
- https://sourceforge.net/p/p7zip/discussion/383043/thread/648d34db/
Modified: 2025-01-10
CVE-2017-17969
Heap-based buffer overflow in the NCompress::NShrink::CDecoder::CodeReal method in 7-Zip before 18.00 and p7zip allows remote attackers to cause a denial of service (out-of-bounds write) or potentially execute arbitrary code via a crafted ZIP archive.
- 1040831
- 1040831
- https://0patch.blogspot.si/2018/02/two-interesting-micropatches-for-7-zip.html
- https://0patch.blogspot.si/2018/02/two-interesting-micropatches-for-7-zip.html
- https://github.com/p7zip-project/p7zip/issues/7
- https://landave.io/2018/01/7-zip-multiple-memory-corruptions-via-rar-and-zip/
- https://landave.io/2018/01/7-zip-multiple-memory-corruptions-via-rar-and-zip/
- [debian-lts-announce] 20180202 [SECURITY] [DLA 1268-1] p7zip security update
- [debian-lts-announce] 20180202 [SECURITY] [DLA 1268-1] p7zip security update
- USN-3913-1
- USN-3913-1
- DSA-4104
- DSA-4104
Modified: 2024-11-21
CVE-2018-10115
Incorrect initialization logic of RAR decoder objects in 7-Zip 18.03 and before can lead to usage of uninitialized memory, allowing remote attackers to cause a denial of service (segmentation fault) or execute arbitrary code via a crafted RAR archive.
- 104132
- 104132
- 1040832
- 1040832
- https://landave.io/2018/05/7-zip-from-uninitialized-memory-to-remote-code-execution/
- https://landave.io/2018/05/7-zip-from-uninitialized-memory-to-remote-code-execution/
- https://sourceforge.net/p/sevenzip/discussion/45797/thread/adc65bfa/
- https://sourceforge.net/p/sevenzip/discussion/45797/thread/adc65bfa/
Modified: 2025-01-10
CVE-2018-5996
Insufficient exception handling in the method NCompress::NRar3::CDecoder::Code of 7-Zip before 18.00 and p7zip can lead to multiple memory corruptions within the PPMd code, allows remote attackers to cause a denial of service (segmentation fault) or execute arbitrary code via a crafted RAR archive.
- 1040831
- 1040831
- https://0patch.blogspot.si/2018/02/two-interesting-micropatches-for-7-zip.html
- https://0patch.blogspot.si/2018/02/two-interesting-micropatches-for-7-zip.html
- https://github.com/p7zip-project/p7zip/issues/32
- https://github.com/p7zip-project/p7zip/issues/8
- https://landave.io/2018/01/7-zip-multiple-memory-corruptions-via-rar-and-zip/
- https://landave.io/2018/01/7-zip-multiple-memory-corruptions-via-rar-and-zip/
Package liburiparser updated to version 0.9.0-alt1 for branch sisyphus in task 216105.
Closed vulnerabilities
BDU:2019-03341
Уязвимость парсера Uriparser, связанная с целочисленным переполнением в функции uriComposeQuery * или uriComposeQueryEx * из-за неконтролируемого умножения, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании
BDU:2020-00731
Уязвимость функции uriComposeQuery парсера Uriparser, связанная с записью за границами буфера памяти, позволяющая нарушителю получить несанкционированный доступ к информации и нарушить ее целостность и доступность
BDU:2020-00732
Уязвимость функции uriResetUri парсера Uriparser, позволяющая нарушителю вызвать отказ в обслуживании
Modified: 2024-11-21
CVE-2018-19198
An issue was discovered in uriparser before 0.9.0. UriQuery.c allows an out-of-bounds write via a uriComposeQuery* or uriComposeQueryEx* function because the '&' character is mishandled in certain contexts.
- RHSA-2019:2280
- RHSA-2019:2280
- https://github.com/uriparser/uriparser/blob/uriparser-0.9.0/ChangeLog
- https://github.com/uriparser/uriparser/blob/uriparser-0.9.0/ChangeLog
- https://github.com/uriparser/uriparser/commit/864f5d4c127def386dd5cc926ad96934b297f04e
- https://github.com/uriparser/uriparser/commit/864f5d4c127def386dd5cc926ad96934b297f04e
- [debian-lts-announce] 20181120 [SECURITY] [DLA 1581-1] uriparser security update
- [debian-lts-announce] 20181120 [SECURITY] [DLA 1581-1] uriparser security update
Modified: 2024-11-21
CVE-2018-19199
An issue was discovered in uriparser before 0.9.0. UriQuery.c allows an integer overflow via a uriComposeQuery* or uriComposeQueryEx* function because of an unchecked multiplication.
- RHSA-2019:2280
- RHSA-2019:2280
- https://github.com/uriparser/uriparser/blob/uriparser-0.9.0/ChangeLog
- https://github.com/uriparser/uriparser/blob/uriparser-0.9.0/ChangeLog
- https://github.com/uriparser/uriparser/commit/f76275d4a91b28d687250525d3a0c5509bbd666f
- https://github.com/uriparser/uriparser/commit/f76275d4a91b28d687250525d3a0c5509bbd666f
- [debian-lts-announce] 20181120 [SECURITY] [DLA 1581-1] uriparser security update
- [debian-lts-announce] 20181120 [SECURITY] [DLA 1581-1] uriparser security update
Modified: 2024-11-21
CVE-2018-19200
An issue was discovered in uriparser before 0.9.0. UriCommon.c allows attempted operations on NULL input via a uriResetUri* function.
- https://github.com/uriparser/uriparser/blob/uriparser-0.9.0/ChangeLog
- https://github.com/uriparser/uriparser/blob/uriparser-0.9.0/ChangeLog
- https://github.com/uriparser/uriparser/commit/f58c25069cf4a986fe17a80c5b38687e31feb539
- https://github.com/uriparser/uriparser/commit/f58c25069cf4a986fe17a80c5b38687e31feb539
- [debian-lts-announce] 20181120 [SECURITY] [DLA 1581-1] uriparser security update
- [debian-lts-announce] 20181120 [SECURITY] [DLA 1581-1] uriparser security update