[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

[SECURITY] [DLA 955-1] rzip security update



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Package        : rzip
Version        : 2.1-1+deb7u1
CVE ID         : CVE-2017-8364
Debian Bug     : 861614

Agostino Sarubbo of Gentoo discovered a heap buffer overflow write
in the rzip program when uncompressing maliciously crafted files.

For Debian 7 "Wheezy", these problems have been fixed in version
2.1-1+deb7u1.

We recommend that you upgrade your rzip packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEEcJymx+vmJZxd92Q+nUbEiOQ2gwIFAlkoZ0UACgkQnUbEiOQ2
gwL6fA/+JE5K39v9YRoNNlq3Q/gGVJ5vqimmd2s4tB++wN7XRwzYsQxGYOjtFtZn
MbF0/zeP6jlY+BVPhVRPavyojfqGIMC4kZ1eQe+GGeiXrBfPtt9vUfBtdEZoP+BE
Po3Ofj/89Zd0iA3taswOMflO2SgkA2i107C4WIo6QCCXYZM+XiP8IISf285rT9lV
sZW3tH2JbNrenCFy4OlP0wP3DlWVfwcv28Jhin6fm4KoWuoSNkx7iEoWr5NwWEKY
3bQEr9u7ULw9tTa7vmI1K3/KeElM4swCcdT6KEgTLIq5al9Z130wNgYwHdm4DST9
hni623VkSTZmHHlA4s4O4KtBjR5+/6Qcii+OaF4d0DQoCrzuojT5p2IFXr7JgAtj
6WDSX5nwoZx6rDpOT2uNdUwmAKvr2XEhyajZQMIrDqXkQc6YgzcNktBEUJ4byk7e
/HTqbtpDDmDddlUttD+T6yF+gXXv9tHFa24fabCU1gCIm+Jop0CA7hDsWtCRl/3f
fYf52JK2mGLRCk7RT9ScfLhdy7VqAWSwD6aHKqLQrSPDul0S89zFCWyzOsQGDzk/
nGPB6ci5v5GT8OkfmQxDxS7wpA/zgUPzJsiiTYdROTYG/SkBy8fUp8yUOBqgvM0j
01l9fGbncDJv7lL7Zokk46E/TveQFGT5wkxpQzEBJVh654G1d/o=
=maWH
-----END PGP SIGNATURE-----


Reply to: