FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2014-9765

This CVE name corresponds to:

Entered Topic
2016-02-16 xdelta3 -- buffer overflow vulnerability

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2014-9765
Phase Assigned(20160208)

Description

Buffer overflow in the main_get_appheader function in xdelta3-main.h in xdelta3 before 3.0.9 allows remote attackers to execute arbitrary code via a crafted input file.

References

Source Reference
MLIST [oss-security] 20160208 CVE request - buffer overflow in xdelta3 before 3.0.9
MLIST [oss-security] 20160208 Re: CVE request - buffer overflow in xdelta3 before 3.0.9
CONFIRM https://github.com/jmacd/xdelta-devel/commit/ef93ff74203e030073b898c05e8b4860b5d09ef2
DEBIAN DSA-3484
SUSE openSUSE-SU-2016:0524
SUSE openSUSE-SU-2016:0530
UBUNTU USN-2901-1