Bug#861614: rzip: CVE-2017-8364

2017-05-26 Thread Emilio Pozuelo Monfort
Control: tags -1 pending Hi, On Fri, 26 May 2017 18:18:59 +0200 Emilio Pozuelo Monfort wrote: > Control: tags -1 patch > > Hi, > > On Mon, 01 May 2017 16:14:08 +0200 Salvatore Bonaccorso > wrote: > > Source: rzip > > Version: 2.1-1 > > Severity: grave > > Tags: security upstream > > Justifi

Bug#861614: rzip: CVE-2017-8364

2017-05-26 Thread Emilio Pozuelo Monfort
Control: tags -1 patch Hi, On Mon, 01 May 2017 16:14:08 +0200 Salvatore Bonaccorso wrote: > Source: rzip > Version: 2.1-1 > Severity: grave > Tags: security upstream > Justification: user security hole > > Hi, > > the following vulnerability was published for rzip, filled with RC > severity d

Bug#861614: rzip: CVE-2017-8364

2017-05-01 Thread Salvatore Bonaccorso
Source: rzip Version: 2.1-1 Severity: grave Tags: security upstream Justification: user security hole Hi, the following vulnerability was published for rzip, filled with RC severity due to the heap overflow write, but no further investigation done so far. CVE-2017-8364[0]: | The read_buf functio