Re: [Slackbuilds-users] p7zip vulnerabilities

2016-05-31 Thread Willy Sudiarto Raharjo
> p7zip 9.20.1 has two security issues : > > CVE-2015-1038: > p7zip 9.20.1 allows remote attackers to write to arbitrary files via a > symlink attack in an archive. > > https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1038 > https://sourceforge.net/p/p7zip/bugs/147/#2f9c > > CVE-2016-2335

[Slackbuilds-users] p7zip vulnerabilities

2016-05-31 Thread Sebastien BALLET
Hello, p7zip 9.20.1 has two security issues : CVE-2015-1038: p7zip 9.20.1 allows remote attackers to write to arbitrary files via a symlink attack in an archive. https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1038 https://sourceforge.net/p/p7zip/bugs/147/#2f9c CVE-2016-2335: 7zip UDF C