Bug#401301: lha: LHa Multiple Vulnerabilities

2006-12-09 Thread Andreas Barth
* Stefan Fritsch ([EMAIL PROTECTED]) [061202 04:55]: > LHA seems to be affected by > CVE-2006-4335 > CVE-2006-4337 > CVE-2006-4338 All these bugs seem to be in gzip, not in lha? Cheers, Andi -- http://home.arcor.de/andreas-barth/ -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subjec

Bug#401301: lha: LHa Multiple Vulnerabilities

2006-12-06 Thread Stefan Fritsch
On Tuesday 05 December 2006 23:48, Moritz Muehlenhoff wrote: > If GNU gzip can handle LHA archives I'm wondering if the non-free > lha is really worth keeping? I don't think gzip can handle LHA archives. It just supports one obscure format that uses LHA's algorithm. BTW, in combination with amav

Bug#401301: lha: LHa Multiple Vulnerabilities

2006-12-05 Thread Moritz Muehlenhoff
On Sat, Dec 02, 2006 at 01:54:57PM +0100, Stefan Fritsch wrote: > Package: lha > Version: 1.14i-10 > Severity: grave > Tags: security > Justification: user security hole > > > LHA seems to be affected by > CVE-2006-4335 > CVE-2006-4337 > CVE-2006-4338 If GNU gzip can handle LHA archives I'm won

Bug#401301: lha: LHa Multiple Vulnerabilities

2006-12-02 Thread Stefan Fritsch
Package: lha Version: 1.14i-10 Severity: grave Tags: security Justification: user security hole LHA seems to be affected by CVE-2006-4335 CVE-2006-4337 CVE-2006-4338 See http://secunia.com/advisories/23153/ for details -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubsc