FS#43131 - [unrtf] CVE-2014-9274 CVE-2014-9275: arbitrary code execution
Attached to Project:
Community Packages
Opened by Levente Polyak (anthraxx) - Tuesday, 16 December 2014, 13:50 GMT
Last edited by Jaroslav Lichtblau (Dragonlord) - Tuesday, 16 December 2014, 19:45 GMT
Opened by Levente Polyak (anthraxx) - Tuesday, 16 December 2014, 13:50 GMT
Last edited by Jaroslav Lichtblau (Dragonlord) - Tuesday, 16 December 2014, 19:45 GMT
|
Details
Summary:
It has been reported [0] that unrtf before version 0.21.7 is vulnerable to possible arbitrary code execution tracked as CVE-2014-9274 [1] CVE-2014-9275 [2]. Description: UnRTF allows remote attackers to cause a denial of service (out-of-bounds memory access and crash) and possibly execute arbitrary code via a crafted RTF file. Mitigation: The problems have been fixed upstream in version 0.21.7 [3]. [0] http://seclists.org/oss-sec/2014/q4/904 [1] https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-9274 [2] https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-9275 [3] http://ftp.gnu.org/gnu/unrtf/unrtf-0.21.7.tar.gz |
This task depends upon
Closed by Jaroslav Lichtblau (Dragonlord)
Tuesday, 16 December 2014, 19:45 GMT
Reason for closing: Fixed
Additional comments about closing: Package updated
unrtf-0.21.7-1
Tuesday, 16 December 2014, 19:45 GMT
Reason for closing: Fixed
Additional comments about closing: Package updated
unrtf-0.21.7-1