From b0a66eacefb208dda861a78aa58848b8496d6e10 Mon Sep 17 00:00:00 2001 From: "Simon L. B. Nielsen" Date: Fri, 26 Nov 2004 20:41:06 +0000 Subject: Document two vulnerabilities in unarj. --- security/vuxml/vuln.xml | 53 +++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 53 insertions(+) (limited to 'security/vuxml/vuln.xml') diff --git a/security/vuxml/vuln.xml b/security/vuxml/vuln.xml index 5c3e1e7c69ca..67ac7616cf54 100644 --- a/security/vuxml/vuln.xml +++ b/security/vuxml/vuln.xml @@ -32,6 +32,59 @@ EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. --> + + unarj -- long filename buffer overflow + + + unarj + 2.43_2 + + + + +

Ludwig Nussel has discovered a buffer overflow + vulnerability in unarj's handling of long filenames which + could potentially lead to execution of arbitrary code with + the permissions of the user running unarj.

+ +
+ + CAN-2004-0947 + 11665 + + + 2004-11-09 + 2004-11-26 + +
+ + + unarj -- directory traversal vulnerability + + + unarj + 2.43_2 + + + + +

unarj has insufficient checks for filenames that contain + ... This can allow an attacker to overwrite + arbitrary files with the permissions of the user running + unarj.

+ +
+ + CAN-2004-1027 + 11436 + http://marc.theaimsgroup.com/?l=full-disclosure&m=109748984030292 + + + 2004-10-10 + 2004-11-26 + +
+ Security Vulnerability With Java Plugin -- cgit v1.2.3