Bug#401301: lha: LHa Multiple Vulnerabilities

2006-12-09 Thread Andreas Barth
* Stefan Fritsch ([EMAIL PROTECTED]) [061202 04:55]: LHA seems to be affected by CVE-2006-4335 CVE-2006-4337 CVE-2006-4338 All these bugs seem to be in gzip, not in lha? Cheers, Andi -- http://home.arcor.de/andreas-barth/ -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject

Bug#401301: lha: LHa Multiple Vulnerabilities

2006-12-06 Thread Stefan Fritsch
On Tuesday 05 December 2006 23:48, Moritz Muehlenhoff wrote: If GNU gzip can handle LHA archives I'm wondering if the non-free lha is really worth keeping? I don't think gzip can handle LHA archives. It just supports one obscure format that uses LHA's algorithm. BTW, in combination with

Bug#401301: lha: LHa Multiple Vulnerabilities

2006-12-05 Thread Moritz Muehlenhoff
On Sat, Dec 02, 2006 at 01:54:57PM +0100, Stefan Fritsch wrote: Package: lha Version: 1.14i-10 Severity: grave Tags: security Justification: user security hole LHA seems to be affected by CVE-2006-4335 CVE-2006-4337 CVE-2006-4338 If GNU gzip can handle LHA archives I'm wondering if

Bug#401301: lha: LHa Multiple Vulnerabilities

2006-12-02 Thread Stefan Fritsch
Package: lha Version: 1.14i-10 Severity: grave Tags: security Justification: user security hole LHA seems to be affected by CVE-2006-4335 CVE-2006-4337 CVE-2006-4338 See http://secunia.com/advisories/23153/ for details -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of