Joined: 25 Feb 2003
Location: Essen, Germany
|Posted: Fri Oct 01, 2004 2:21 pm Post subject: [ GLSA 200410-01 ] sharutils: Buffer overflows in shar.c and
|Gentoo Linux Security Advisory
Title: sharutils: Buffer overflows in shar.c and unshar.c (GLSA 200410-01)
Date: October 01, 2004
Updated: May 22, 2006
sharutils contains two buffer overflow vulnerabilities that could lead to
arbitrary code execution.
sharutils contains utilities to manage shell archives.
Vulnerable: <= 4.2.1-r9
Unaffected: >= 4.2.1-r10
Architectures: All supported architectures
sharutils contains two buffer overflows. Ulf Harnhammar discovered a
buffer overflow in shar.c, where the length of data returned by the wc
command is not checked. Florian Schilhabel discovered another buffer
overflow in unshar.c.
An attacker could exploit these vulnerabilities to execute arbitrary
code as the user running one of the sharutils programs.
There is no known workaround at this time.
All sharutils users should upgrade to the latest version:
|# emerge sync
# emerge -pv ">=app-arch/sharutils-4.2.1-r10"
# emerge ">=app-arch/sharutils-4.2.1-r10"
Debian Bug #265904
Last edited by GLSA on Sun Aug 15, 2010 4:17 am; edited 4 times in total