FS#44411 - [arj] CVE-2015-2782: buffer overflow

Attached to Project: Community Packages
Opened by Remi Gacogne (rgacogne) - Tuesday, 31 March 2015, 08:56 GMT
Last edited by Alexander F. Rødseth (xyproto) - Wednesday, 22 April 2015, 13:35 GMT
Task Type Bug Report
Category Packages
Status Closed
Assigned To Alexander F. Rødseth (xyproto)
Architecture All
Severity High
Priority Normal
Reported Version
Due in Version Undecided
Due Date Undecided
Percent Complete 100%
Votes 0
Private No

Details

Hello,

A vulnerability has been found [1] in arj <= 3.10.22. I don't think a new version is going to be released, so we might want to backport the patch proposed by Debian [2].

[1]: http://www.openwall.com/lists/oss-security/2015/03/29/1
[2]: http://git.hadrons.org/gitweb/?p=debian/pkgs/arj.git;a=blob_plain;f=debian/patches/security-afl.patch
This task depends upon

Closed by  Alexander F. Rødseth (xyproto)
Wednesday, 22 April 2015, 13:35 GMT
Reason for closing:  Upstream
Additional comments about closing:  Moved to AUR, see https://lists.archlinux.org/pipermail/au r-general/2015-April/030503.html
Comment by Alexander F. Rødseth (xyproto) - Saturday, 04 April 2015, 10:05 GMT
Thanks for reporting! I'll look into this.

Loading...