2020-07-18
ALT-BU-2020-3925-1
Branch sisyphus update bulletin.
Package pve-manager updated to version 6.0.7-alt10 for branch sisyphus in task 255007.
Closed bugs
API возвращает пустое поле version
Package gem-rubocop updated to version 0.88.0-alt1.1 for branch sisyphus in task 255031.
Closed bugs
Неработоспособен изкоробки
Closed vulnerabilities
Published: 2016-11-12
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2016-9296
A null pointer dereference bug affects the 16.02 and many old versions of p7zip. A lack of null pointer check for the variable folders.PackPositions in function CInArchive::ReadAndDecodePackedStreams in CPP/7zip/Archive/7z/7zIn.cpp, as used in the 7z.so library and in 7z applications, will cause a crash and a denial of service when decoding malformed 7z files.
Severity: HIGH (7.5)
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
References:
- 94294
- 94294
- https://github.com/yangke/7zip-null-pointer-dereference
- https://github.com/yangke/7zip-null-pointer-dereference
- https://sourceforge.net/p/p7zip/bugs/185/
- https://sourceforge.net/p/p7zip/bugs/185/
- https://sourceforge.net/p/p7zip/discussion/383043/thread/648d34db/
- https://sourceforge.net/p/p7zip/discussion/383043/thread/648d34db/