Gentoo Archives: gentoo-announce

From: Sean Amoss <ackle@g.o>
To: gentoo-announce@g.o
Subject: [gentoo-announce] [ GLSA 201203-23 ] libzip: Multiple vulnerabilities
Date: Thu, 29 Mar 2012 11:50:48
Message-Id: 4F744AA8.8010500@gentoo.org
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 201203-23
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 http://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: Normal
8 Title: libzip: Multiple vulnerabilities
9 Date: March 29, 2012
10 Bugs: #409117
11 ID: 201203-23
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 Multiple vulnerabilities have been found in libzip, the worst of which
19 might allow execution of arbitrary code.
20
21 Background
22 ==========
23
24 libzip is a library for manipulating zip archives.
25
26 Affected packages
27 =================
28
29 -------------------------------------------------------------------
30 Package / Vulnerable / Unaffected
31 -------------------------------------------------------------------
32 1 dev-libs/libzip < 0.10.1 >= 0.10.1
33
34 Description
35 ===========
36
37 Two vulnerabilities have been found in the "_zip_readcdir()" function
38 in zip_open.c of libzip:
39
40 * An incorrect loop construct, which could cause a heap-based buffer
41 overflow (CVE-2012-1162).
42 * An integer overflow, which may not restrict operations within the
43 memory buffer (CVE-2012-1163).
44
45 Impact
46 ======
47
48 A remote attacker could entice a user to open a specially crafted ZIP
49 file, possibly resulting in execution of arbitrary code with the
50 privileges of the process, a Denial of Service condition, or
51 information leaks.
52
53 Workaround
54 ==========
55
56 There is no known workaround at this time.
57
58 Resolution
59 ==========
60
61 All libzip users should upgrade to the latest version:
62
63 # emerge --sync
64 # emerge --ask --oneshot --verbose ">=dev-libs/libzip-0.10.1"
65
66 References
67 ==========
68
69 [ 1 ] CVE-2012-1162
70 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1162
71 [ 2 ] CVE-2012-1163
72 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1163
73
74 Availability
75 ============
76
77 This GLSA and any updates to it are available for viewing at
78 the Gentoo Security Website:
79
80 http://security.gentoo.org/glsa/glsa-201203-23.xml
81
82 Concerns?
83 =========
84
85 Security is a primary focus of Gentoo Linux and ensuring the
86 confidentiality and security of our users' machines is of utmost
87 importance to us. Any security concerns should be addressed to
88 security@g.o or alternatively, you may file a bug at
89 https://bugs.gentoo.org.
90
91 License
92 =======
93
94 Copyright 2012 Gentoo Foundation, Inc; referenced text
95 belongs to its owner(s).
96
97 The contents of this document are licensed under the
98 Creative Commons - Attribution / Share Alike license.
99
100 http://creativecommons.org/licenses/by-sa/2.5

Attachments

File name MIME type
signature.asc application/pgp-signature