~ubuntu-security/ubuntu-cve-tracker/master

« back to all changes in this revision

Viewing changes to active/CVE-2016-9296

  • Committer: Steve Beattie
  • Date: 2019-02-19 06:18:27 UTC
  • Revision ID: sbeattie@ubuntu.com-20190219061827-oh57fzcfc1u9dlfk
The ubuntu-cve-tracker project has been converted to git.

Please use 'git clone https://git.launchpad.net/ubuntu-cve-tracker' to
get the converted tree.

Show diffs side-by-side

added added

removed removed

Lines of Context:
1
 
Candidate: CVE-2016-9296
2
 
PublicDate: 2016-11-11
3
 
References:
4
 
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9296
5
 
 https://sourceforge.net/p/p7zip/bugs/185/
6
 
 https://github.com/yangke/7zip-null-pointer-dereference
7
 
 https://sourceforge.net/p/p7zip/discussion/383043/thread/648d34db/
8
 
Description:
9
 
 A null pointer dereference bug affects the 16.02 and many old versions of
10
 
 p7zip. A lack of null pointer check for the variable folders.PackPositions
11
 
 in function CInArchive::ReadAndDecodePackedStreams in
12
 
 CPP/7zip/Archive/7z/7zIn.cpp, as used in the 7z.so library and in 7z
13
 
 applications, will cause a crash and a denial of service when decoding
14
 
 malformed 7z files.
15
 
Ubuntu-Description:
16
 
Notes:
17
 
 sbeattie> crasher example is in sourceforge bug report
18
 
Bugs:
19
 
 http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=844344
20
 
Priority: low
21
 
Discovered-by:
22
 
Assigned-to:
23
 
 
24
 
Patches_p7zip:
25
 
upstream_p7zip: needs-triage
26
 
precise_p7zip: ignored (reached end-of-life)
27
 
precise/esm_p7zip: DNE (precise was needed)
28
 
trusty_p7zip: needed
29
 
vivid/stable-phone-overlay_p7zip: DNE
30
 
vivid/ubuntu-core_p7zip: DNE
31
 
xenial_p7zip: needed
32
 
yakkety_p7zip: ignored (reached end-of-life)
33
 
zesty_p7zip: ignored (reached end-of-life)
34
 
artful_p7zip: needed
35
 
bionic_p7zip: needed
36
 
devel_p7zip: needed