FS#44411 - [arj] CVE-2015-2782: buffer overflow
Attached to Project:
Community Packages
Opened by Remi Gacogne (rgacogne) - Tuesday, 31 March 2015, 08:56 GMT
Last edited by Alexander F. Rødseth (xyproto) - Wednesday, 22 April 2015, 13:35 GMT
Opened by Remi Gacogne (rgacogne) - Tuesday, 31 March 2015, 08:56 GMT
Last edited by Alexander F. Rødseth (xyproto) - Wednesday, 22 April 2015, 13:35 GMT
|
Details
Hello,
A vulnerability has been found [1] in arj <= 3.10.22. I don't think a new version is going to be released, so we might want to backport the patch proposed by Debian [2]. [1]: http://www.openwall.com/lists/oss-security/2015/03/29/1 [2]: http://git.hadrons.org/gitweb/?p=debian/pkgs/arj.git;a=blob_plain;f=debian/patches/security-afl.patch |
This task depends upon
Closed by Alexander F. Rødseth (xyproto)
Wednesday, 22 April 2015, 13:35 GMT
Reason for closing: Upstream
Additional comments about closing: Moved to AUR, see https://lists.archlinux.org/pipermail/au r-general/2015-April/030503.html
Wednesday, 22 April 2015, 13:35 GMT
Reason for closing: Upstream
Additional comments about closing: Moved to AUR, see https://lists.archlinux.org/pipermail/au r-general/2015-April/030503.html
Comment by
Alexander F. Rødseth (xyproto) -
Saturday, 04 April 2015, 10:05 GMT
Thanks for reporting! I'll look into this.