LWN.net Logo

squashfs-tools: two code execution flaws

Package(s):squashfs-tools CVE #(s):CVE-2012-4024 CVE-2012-4025
Created:December 19, 2012 Updated:January 7, 2013
Description:

From the Red Hat bugzilla entries [1, 2]:

CVE-2012-4024: Stack-based buffer overflow in the get_component function in unsquashfs.c in unsquashfs in Squashfs 4.2 and earlier allows remote attackers to execute arbitrary code via a crafted list file (aka a crafted file for the -ef option). NOTE: probably in most cases, the list file is a trusted file constructed by the program's user; however, there are some realistic situations in which a list file would be obtained from an untrusted remote source.

CVE-2012-4025: Integer overflow in the queue_init function in unsquashfs.c in unsquashfs in Squashfs 4.2 and earlier allows remote attackers to execute arbitrary code via a crafted block_log field in the superblock of a .sqsh file, leading to a heap-based buffer overflow.

Alerts:
Fedora FEDORA-2012-19227 2012-12-13
Fedora FEDORA-2012-19203 2012-12-13
Mageia MGASA-2013-0001 2013-01-05

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds