SUSE-SU-2018:2978-1 -- SLES unzipID: oval:org.secpod.oval:def:89043924 | Date: (C)2021-03-05 (M)2021-06-02 |
Class: PATCH | Family: unix |
This update for unzip fixes the following security issues: - CVE-2014-9913: Specially crafted zip files could trigger invalid memory writes possibly resulting in DoS or corruption - CVE-2015-7696: Specially crafted zip files with password protection could trigger a crash and lead to denial of service - CVE-2015-7697: Specially crafted zip files could trigger an endless loop and lead to denial of service - CVE-2016-9844: Specially crafted zip files could trigger invalid memory writes possibly resulting in DoS or corruption - CVE-2018-1000035: Prevent heap-based buffer overflow in the processing of password-protected archives that allowed an attacker to perform a denial of service or to possibly achieve code execution . - CVE-2014-9636: Prevent denial of service via an extra field with an uncompressed size smaller than the compressed field size in a zip archive that advertises STORED method compression . This non-security issue was fixed: +- Allow processing of Windows zip64 archives
Platform: |
SUSE Linux Enterprise Server 12 SP3 |