Out-of-bounds read In squashfs-tools
Description
Integer overflow in the queue_init function in unsquashfs.c in unsquashfs in Squashfs 4.2 and earlier allows remote attackers to execute arbitrary code via a crafted block_log field in the superblock of a .sqsh file, leading to a heap-based buffer overflow.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
debian 13 | 1:4.2+20121212-1 | ||
debian 12 | 1:4.2+20121212-1 | ||
debian 14 | 1:4.2+20121212-1 | ||
debian 11 | 1:4.2+20121212-1 | ||
rpm rhel6 | - | - |
Aliases
1. 2. 3. 4. 5.