Bugzilla – Full Text Bug Listing |
Summary: | VUL-1: CVE-2017-8364: rzip: heap-based buffer overflow in read_buf (stream.c) via crafted archive | ||
---|---|---|---|
Product: | [Novell Products] SUSE Security Incidents | Reporter: | Mikhail Kasimov <mikhail.kasimov> |
Component: | Incidents | Assignee: | Andreas Schwab <schwab> |
Status: | RESOLVED FIXED | QA Contact: | Security Team bot <security-team> |
Severity: | Normal | ||
Priority: | P4 - Low | CC: | astieger |
Version: | unspecified | ||
Target Milestone: | unspecified | ||
Hardware: | Other | ||
OS: | openSUSE 42.2 | ||
URL: | https://smash.suse.de/issue/184590/ | ||
Whiteboard: | |||
Found By: | --- | Services Priority: | |
Business Priority: | Blocker: | --- | |
Marketing QA Status: | --- | IT Deployment: | --- |
Attachments: | 00277-rzip-heap-overflow-read_buf_reproducer |
Description
Mikhail Kasimov
2017-04-29 15:39:16 UTC
openSUSE only. CVE-2017-8364: https://nvd.nist.gov/vuln/detail/CVE-2017-8364 This is an autogenerated message for OBS integration: This bug (1036941) was mentioned in https://build.opensuse.org/request/show/492818 42.1 / rzip https://build.opensuse.org/request/show/492819 42.2 / rzip openSUSE-SU-2017:1275-1: An update that fixes one vulnerability is now available. Category: security (low) Bug References: 1036941 CVE References: CVE-2017-8364 Sources used: openSUSE Leap 42.2 (src): rzip-2.1-151.3.1 openSUSE Leap 42.1 (src): rzip-2.1-151.1 Fixed. |