ALT-PU-2016-1082-1
Package cabextract updated to version 1.6-alt1 for branch sisyphus in task 158192.
Closed vulnerabilities
BDU:2020-01873
Уязвимость функции kwajd_read_headers библиотеки Libmspack и утилиты разархивации CAB-файлов СabExtract, позволяющая нарушителю вызвать отказ в обслуживании
Modified: 2024-11-21
CVE-2018-14679
An issue was discovered in mspack/chmd.c in libmspack before 0.7alpha. There is an off-by-one error in the CHM PMGI/PMGL chunk number validity checks, which could lead to denial of service (uninitialized data dereference and application crash).
- http://www.openwall.com/lists/oss-security/2018/07/26/1
- 1041410
- RHSA-2018:3327
- RHSA-2018:3505
- https://bugs.debian.org/904802
- https://github.com/kyz/libmspack/commit/72e70a921f0f07fee748aec2274b30784e1d312a
- [debian-lts-announce] 20180806 [SECURITY] [DLA-1460-1] libmspack security update
- GLSA-201903-20
- USN-3728-1
- USN-3728-2
- USN-3728-3
- USN-3789-2
- DSA-4260
- http://www.openwall.com/lists/oss-security/2018/07/26/1
- DSA-4260
- USN-3789-2
- USN-3728-3
- USN-3728-2
- USN-3728-1
- GLSA-201903-20
- [debian-lts-announce] 20180806 [SECURITY] [DLA-1460-1] libmspack security update
- https://github.com/kyz/libmspack/commit/72e70a921f0f07fee748aec2274b30784e1d312a
- https://bugs.debian.org/904802
- RHSA-2018:3505
- RHSA-2018:3327
- 1041410
Modified: 2024-11-21
CVE-2018-14680
An issue was discovered in mspack/chmd.c in libmspack before 0.7alpha. It does not reject blank CHM filenames.
- http://www.openwall.com/lists/oss-security/2018/07/26/1
- 1041410
- RHSA-2018:3327
- RHSA-2018:3505
- https://bugs.debian.org/904801
- https://github.com/kyz/libmspack/commit/72e70a921f0f07fee748aec2274b30784e1d312a
- [debian-lts-announce] 20180806 [SECURITY] [DLA-1460-1] libmspack security update
- GLSA-201903-20
- USN-3728-1
- USN-3728-2
- USN-3728-3
- USN-3789-2
- DSA-4260
- http://www.openwall.com/lists/oss-security/2018/07/26/1
- DSA-4260
- USN-3789-2
- USN-3728-3
- USN-3728-2
- USN-3728-1
- GLSA-201903-20
- [debian-lts-announce] 20180806 [SECURITY] [DLA-1460-1] libmspack security update
- https://github.com/kyz/libmspack/commit/72e70a921f0f07fee748aec2274b30784e1d312a
- https://bugs.debian.org/904801
- RHSA-2018:3505
- RHSA-2018:3327
- 1041410
Modified: 2024-11-21
CVE-2018-14681
An issue was discovered in kwajd_read_headers in mspack/kwajd.c in libmspack before 0.7alpha. Bad KWAJ file header extensions could cause a one or two byte overwrite.
- http://www.openwall.com/lists/oss-security/2018/07/26/1
- 1041410
- RHSA-2018:3327
- RHSA-2018:3505
- https://bugs.debian.org/904799
- https://github.com/kyz/libmspack/commit/0b0ef9344255ff5acfac6b7af09198ac9c9756c8
- [debian-lts-announce] 20180806 [SECURITY] [DLA-1460-1] libmspack security update
- GLSA-201903-20
- USN-3728-1
- USN-3728-2
- USN-3728-3
- USN-3789-2
- DSA-4260
- http://www.openwall.com/lists/oss-security/2018/07/26/1
- DSA-4260
- USN-3789-2
- USN-3728-3
- USN-3728-2
- USN-3728-1
- GLSA-201903-20
- [debian-lts-announce] 20180806 [SECURITY] [DLA-1460-1] libmspack security update
- https://github.com/kyz/libmspack/commit/0b0ef9344255ff5acfac6b7af09198ac9c9756c8
- https://bugs.debian.org/904799
- RHSA-2018:3505
- RHSA-2018:3327
- 1041410
Modified: 2024-11-21
CVE-2018-14682
An issue was discovered in mspack/chmd.c in libmspack before 0.7alpha. There is an off-by-one error in the TOLOWER() macro for CHM decompression.
- http://www.openwall.com/lists/oss-security/2018/07/26/1
- 1041410
- RHSA-2018:3327
- RHSA-2018:3505
- https://bugs.debian.org/904800
- https://github.com/kyz/libmspack/commit/4fd9ccaa54e1aebde1e4b95fb0163b699fd7bcc8
- [debian-lts-announce] 20180806 [SECURITY] [DLA-1460-1] libmspack security update
- GLSA-201903-20
- USN-3728-1
- USN-3728-2
- USN-3728-3
- USN-3789-2
- DSA-4260
- http://www.openwall.com/lists/oss-security/2018/07/26/1
- DSA-4260
- USN-3789-2
- USN-3728-3
- USN-3728-2
- USN-3728-1
- GLSA-201903-20
- [debian-lts-announce] 20180806 [SECURITY] [DLA-1460-1] libmspack security update
- https://github.com/kyz/libmspack/commit/4fd9ccaa54e1aebde1e4b95fb0163b699fd7bcc8
- https://bugs.debian.org/904800
- RHSA-2018:3505
- RHSA-2018:3327
- 1041410