Oval Definition:oval:org.opensuse.security:def:59529
Revision Date:2021-08-25Version:1
Title:Security update for unrar (Moderate)
Description:

This update for unrar to version 5.6.1 fixes several issues.

These security issues were fixed:

- CVE-2017-12938: Prevent remote attackers to bypass a directory-traversal protection mechanism via vectors involving a symlink to the . directory, a symlink to the .. directory, and a regular file (bsc#1054038). - CVE-2017-12940: Prevent out-of-bounds read in the EncodeFileName::Decode call within the Archive::ReadHeader15 function (bsc#1054038). - CVE-2017-12941: Prevent an out-of-bounds read in the Unpack::Unpack20 function (bsc#1054038). - CVE-2017-12942: Prevent a buffer overflow in the Unpack::LongLZ function (bsc#1054038). - CVE-2017-20006: Fixed heap-based buffer overflow in Unpack:CopyString (bsc#1187974).

These non-security issues were fixed:

- Added extraction support for .LZ archives created by Lzip compressor - Enable unpacking of files in ZIP archives compressed with XZ algorithm and encrypted with AES - Added support for PAX extended headers inside of TAR archive - If RAR recovery volumes (.rev files) are present in the same folder as usual RAR volumes, archive test command verifies .rev contents after completing testing .rar files - By default unrar skips symbolic links with absolute paths in link target when extracting unless -ola command line switch is specified - Added support for AES-NI CPU instructions - Support for a new RAR 5.0 archiving format - Wildcard exclusion mask for folders - Prevent conditional jumps depending on uninitialised values (bsc#1046882)
Family:unixClass:patch
Status:Reference(s):1046856
1046882
1054038
1056427
1068032
1068648
1075087
1080157
1085449
1087082
1090953
1091041
1092289
1093215
1093311
1094019
1112758
1114674
1131886
1144903
1153108
1153158
1153161
1154862
1164860
1168994
1172405
1173991
1174117
1174284
1175626
1175656
1175686
1187974
CVE-2010-2240
CVE-2012-6706
CVE-2013-1940
CVE-2013-4396
CVE-2013-6424
CVE-2014-0004
CVE-2014-4362
CVE-2014-8091
CVE-2014-8092
CVE-2014-8093
CVE-2014-8094
CVE-2014-8095
CVE-2014-8096
CVE-2014-8097
CVE-2014-8098
CVE-2014-8099
CVE-2014-8100
CVE-2014-8101
CVE-2014-8102
CVE-2014-8103
CVE-2015-0255
CVE-2015-3164
CVE-2015-3418
CVE-2017-1000083
CVE-2017-12938
CVE-2017-12940
CVE-2017-12941
CVE-2017-12942
CVE-2017-16844
CVE-2017-20006
CVE-2017-2624
CVE-2018-1417
CVE-2018-1417
CVE-2018-16839
CVE-2018-18311
CVE-2018-2783
CVE-2018-2783
CVE-2018-2790
CVE-2018-2790
CVE-2018-2794
CVE-2018-2794
CVE-2018-2795
CVE-2018-2795
CVE-2018-2796
CVE-2018-2796
CVE-2018-2797
CVE-2018-2797
CVE-2018-2798
CVE-2018-2798
CVE-2018-2799
CVE-2018-2799
CVE-2018-2800
CVE-2018-2800
CVE-2018-2814
CVE-2018-2814
CVE-2018-2825
CVE-2018-2826
CVE-2018-3639
CVE-2019-10220
CVE-2019-17133
CVE-2019-17498
CVE-2020-10713
CVE-2020-13935
CVE-2020-15663
CVE-2020-15664
CVE-2020-15670
CVE-2020-1935
CVE-2020-8022
SUSE-SU-2017:3428-1
SUSE-SU-2018:0173-1
SUSE-SU-2018:1764-1
SUSE-SU-2019:0996-1
SUSE-SU-2019:2264-1
SUSE-SU-2019:2936-1
SUSE-SU-2020:1791-1
SUSE-SU-2020:2544-1
SUSE-SU-2020:2611-1
SUSE-SU-2020:2627-1
Platform(s):openSUSE Leap 15.0
openSUSE Leap 15.1
SUSE Linux Enterprise Server 12 SP2-BCL
SUSE Linux Enterprise Server 12 SP2-ESPOS
SUSE Linux Enterprise Server 12 SP3
SUSE Linux Enterprise Server 12 SP3-BCL
SUSE Linux Enterprise Server 12 SP3-ESPOS
SUSE Linux Enterprise Server 12 SP3-LTSS
SUSE Linux Enterprise Server 12 SP3-TERADATA
SUSE Linux Enterprise Server 12 SP4
SUSE Linux Enterprise Server 12 SP4-ESPOS
SUSE OpenStack Cloud 8
SUSE OpenStack Cloud 9
SUSE OpenStack Cloud Crowbar 8
Product(s):
Definition Synopsis
  • openSUSE Leap 15.0 is installed
  • AND libid3tag0-0.15.1b-lp150.3 is installed
  • Definition Synopsis
  • openSUSE Leap 15.1 is installed
  • AND dosbox-0.74.3-lp151.3.3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-BCL is installed
  • AND Package Information
  • perl-5.18.2-12.20 is installed
  • OR perl-32bit-5.18.2-12.20 is installed
  • OR perl-base-5.18.2-12.20 is installed
  • OR perl-doc-5.18.2-12.20 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-ESPOS is installed
  • AND Package Information
  • java-1_8_0-ibm-1.8.0_sr5.15-30.33 is installed
  • OR java-1_8_0-ibm-alsa-1.8.0_sr5.15-30.33 is installed
  • OR java-1_8_0-ibm-devel-1.8.0_sr5.15-30.33 is installed
  • OR java-1_8_0-ibm-plugin-1.8.0_sr5.15-30.33 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3 is installed
  • AND davfs2-1.5.2-2 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-BCL is installed
  • AND Package Information
  • git-2.26.2-27.36 is installed
  • OR git-core-2.26.2-27.36 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-ESPOS is installed
  • AND Package Information
  • xen-4.9.4_04-3.56 is installed
  • OR xen-doc-html-4.9.4_04-3.56 is installed
  • OR xen-libs-4.9.4_04-3.56 is installed
  • OR xen-libs-32bit-4.9.4_04-3.56 is installed
  • OR xen-tools-4.9.4_04-3.56 is installed
  • OR xen-tools-domU-4.9.4_04-3.56 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-LTSS is installed
  • AND mailman-2.1.17-3.20 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-TERADATA is installed
  • AND Package Information
  • libzypp-16.17.20-2.33 is installed
  • OR zypper-1.13.45-21.21 is installed
  • OR zypper-log-1.13.45-21.21 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP4 is installed
  • AND Package Information
  • crash-7.2.1-2 is installed
  • OR crash-kmp-default-7.2.1_k4.12.14_94.41-2 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP4-ESPOS is installed
  • AND unrar-5.6.1-4.5.1 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud 8 is installed
  • AND Package Information
  • MozillaFirefox-78.2.0-112.19 is installed
  • OR MozillaFirefox-devel-78.2.0-112.19 is installed
  • OR MozillaFirefox-translations-common-78.2.0-112.19 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud 9 is installed
  • AND python-SQLAlchemy-1.2.10-3.3 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud Crowbar 8 is installed
  • AND shim-15+git47-25.11 is installed
  • BACK