Overview

Request 626498 superseded

- Update to version 0.7 (bsc#1103032):
* Fix 1 or 2 byte overwrite by bad KWAJ file header extensions
(CVE-2018-14681).
* Fix 1 byte overread by character U+0100 in a CHM filename
(CVE-2018-14682).
* Reject blank CHM filenames (CVE-2018-14680).
* Fix off-by-1 in CHM PMGI/PMGL chunk number validity checks,
which could cause a crash (CVE-2018-14679).

Loading...
Request History
Stanislav Brabec's avatar

sbrabec created request

- Update to version 0.7 (bsc#1103032):
* Fix 1 or 2 byte overwrite by bad KWAJ file header extensions
(CVE-2018-14681).
* Fix 1 byte overread by character U+0100 in a CHM filename
(CVE-2018-14682).
* Reject blank CHM filenames (CVE-2018-14680).
* Fix off-by-1 in CHM PMGI/PMGL chunk number validity checks,
which could cause a crash (CVE-2018-14679).


Factory Auto's avatar

factory-auto declined review

Output of check script:
ERROR: Failed to download "https://www.cabextract.org.uk/libmspack/libmspack-0.7alpha.tar.gz"
Source URLs are not valid. Try "osc service localrun download_files"


Factory Auto's avatar

factory-auto declined request

Output of check script:
ERROR: Failed to download "https://www.cabextract.org.uk/libmspack/libmspack-0.7alpha.tar.gz"
Source URLs are not valid. Try "osc service localrun download_files"


Stanislav Brabec's avatar

sbrabec reopened request

Please accept with the problem. According to the upstream web server maintainer, it is not intended change but a temporary problem.


Factory Auto's avatar

factory-auto declined review

Output of check script:
ERROR: Failed to download "https://www.cabextract.org.uk/libmspack/libmspack-0.7alpha.tar.gz"
Source URLs are not valid. Try "osc service localrun download_files"


Factory Auto's avatar

factory-auto declined request

Output of check script:
ERROR: Failed to download "https://www.cabextract.org.uk/libmspack/libmspack-0.7alpha.tar.gz"
Source URLs are not valid. Try "osc service localrun download_files"


Stanislav Brabec's avatar

sbrabec superseded request

New update fixes this problem as well.

openSUSE Build Service is sponsored by