[Bug 84657] Re: Security update for rar/unrar (CVE-2007-0855)

Martin Meredith ubuntu at sourceguru.net
Mon Feb 12 11:05:51 GMT 2007


Quote from email

All these changes in rarvm.cpp code are related to endianness issue
on big endian computers. So users may notice these fixes only on big
endian machine.

Besides, I forgot to mention that real vulnerability was fixed
in GetPassword function in consio.cpp. So if you use 3.6.x version
of this function, please upgrade it to 3.7.3 code.

-- 
Security update for rar/unrar (CVE-2007-0855)
https://launchpad.net/bugs/84657



More information about the ubuntu-archive mailing list