Bug 909214 (CVE-2014-8139) - VUL-0: CVE-2014-8139: unzip: input sanitization errors
Summary: VUL-0: CVE-2014-8139: unzip: input sanitization errors
Status: RESOLVED FIXED
Alias: CVE-2014-8139
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Minor
Target Milestone: ---
Deadline: 2015-01-29
Assignee: Security Team bot
QA Contact: Security Team bot
URL:
Whiteboard: maint:running:60227:moderate maint:re...
Keywords:
Depends on:
Blocks:
 
Reported: 2014-12-10 09:48 UTC by Alexander Bergmann
Modified: 2019-05-01 16:34 UTC (History)
4 users (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Comment 3 Swamp Workflow Management 2014-12-10 23:00:26 UTC
bugbot adjusting priority
Comment 12 Swamp Workflow Management 2015-01-12 10:04:53 UTC
SUSE-SU-2015:0026-1: An update that fixes three vulnerabilities is now available.

Category: security (moderate)
Bug References: 909214
CVE References: CVE-2014-8139,CVE-2014-8140,CVE-2014-8141
Sources used:
SUSE Linux Enterprise Server 12 (src):    unzip-6.00-28.1
SUSE Linux Enterprise Desktop 12 (src):    unzip-6.00-28.1
Comment 13 Marcus Meissner 2015-01-14 08:10:57 UTC
http://seclists.org/oss-sec/2014/q4/1127

 [oCERT-2014-011] UnZip input sanitization errors 

Description:

The UnZip tool is an open source extraction utility for archives compressed in
the zip format.

The unzip command line tool is affected by heap-based buffer overflows within
the CRC32 verification, the test_compr_eb() and the getZip64Data() functions.
The input errors may result in in arbitrary code execution.

A specially crafted zip file, passed to unzip -t, can be used to trigger the
vulnerability.

Affected version:

UnZip <= 6.0

Fixed version:

UnZip, N/A

Credit: vulnerability report received from the Google Security Team.

CVE: CVE-2014-8139 (CRC32 heap overflow), CVE-2014-8140 (test_compr_eb),
     CVE-2014-8141 (getZip64Data)

Timeline:

2014-12-03: vulnerability report received
2014-12-03: contacted maintainer
2014-12-03: first patch provided by maintainer
2014-12-04: report provides additional reproducers
2014-12-03: second patch provided by maintainer
2014-12-04: reporter confirms patch
2014-12-10: contacted affected vendors
2014-12-12: assigned CVEs
2014-12-22: advisory release

References:
http://www.info-zip.org/UnZip.html

Permalink:
http://www.ocert.org/advisories/ocert-2014-011.html

-- 
Andrea Barisani |                Founder & Project Coordinator
          oCERT | OSS Computer Security Incident Response Team
Comment 15 Swamp Workflow Management 2015-01-15 09:58:24 UTC
An update workflow for this issue was started.
This issue was rated as moderate.
Please submit fixed packages until 2015-01-29.
When done, reassign the bug to security-team@suse.de.
https://swamp.suse.de/webswamp/wf/60227
Comment 17 Swamp Workflow Management 2015-01-16 18:04:51 UTC
SUSE-SU-2015:0070-1: An update that fixes three vulnerabilities is now available.

Category: security (moderate)
Bug References: 909214
CVE References: CVE-2014-8139,CVE-2014-8140,CVE-2014-8141
Sources used:
SUSE Linux Enterprise Server 11 SP3 for VMware (src):    unzip-6.00-11.9.1
SUSE Linux Enterprise Server 11 SP3 (src):    unzip-6.00-11.9.1
SUSE Linux Enterprise Desktop 11 SP3 (src):    unzip-6.00-11.9.1
Comment 18 Marcus Meissner 2015-01-23 13:35:09 UTC
Can you also submit fixes for openSUSE 13.1, 13.2 and factory?
Comment 19 Bernhard Wiedemann 2015-01-26 16:00:07 UTC
This is an autogenerated message for OBS integration:
This bug (909214) was mentioned in
https://build.opensuse.org/request/show/282877 13.2+13.1 / unzip-rcc+unzip
Comment 20 Thorsten Behrens 2015-01-27 09:17:46 UTC
(In reply to Bernhard Wiedemann from comment #19)
> This is an autogenerated message for OBS integration:
> This bug (909214) was mentioned in
> https://build.opensuse.org/request/show/282877 13.2+13.1 / unzip-rcc+unzip
>
And sr#282876 for factory.
Comment 21 Swamp Workflow Management 2015-02-09 09:04:53 UTC
openSUSE-SU-2015:0240-1: An update that fixes three vulnerabilities is now available.

Category: security (moderate)
Bug References: 909214
CVE References: CVE-2014-8139,CVE-2014-8140,CVE-2014-8141
Sources used:
openSUSE 13.2 (src):    unzip-6.00-26.4.1, unzip-rcc-6.00-26.4.1
openSUSE 13.1 (src):    unzip-6.00-24.4.1, unzip-rcc-6.00-24.4.1
Comment 22 Swamp Workflow Management 2015-02-25 22:05:05 UTC
SUSE-SU-2015:0377-1: An update that fixes two vulnerabilities is now available.

Category: security (moderate)
Bug References: 909214,914442
CVE References: CVE-2014-8139,CVE-2014-9636
Sources used:
SUSE Linux Enterprise Server 11 SP3 for VMware (src):    unzip-6.00-11.13.1
SUSE Linux Enterprise Server 11 SP3 (src):    unzip-6.00-11.13.1
SUSE Linux Enterprise Desktop 11 SP3 (src):    unzip-6.00-11.13.1
Comment 23 Marcus Meissner 2015-03-17 16:03:47 UTC
released