Bug#591552: Two security issues

2010-08-03 Thread Eric Sharkey
I'm aware of these issues and will be uploading a new cabextract package shortly. I'd just like to note that the potential for security vulnerabilities here seems very small to me. Eric Sharkey shar...@debian.org -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subje

Bug#591552: Two security issues

2010-08-03 Thread Moritz Muehlenhoff
Package: cabextract Version: 1.2-4 Severity: grave Tags: security The following was sent to us by Red Hat: 1, Infinite loop in MS-ZIP and Quantum decoders (minor issue): (CVE-2010-2800) A deficiency has been reported in the way cabextract extracted certain Cabinet (*.cab) files, using the MZ-ZIP