Bug#874060: unrar-free: CVE-2017-14122: stack overread vulnerability

2017-10-14 Thread Ying-Chun Liu (PaulLiu)
On 2017年10月14日 21:43, Ying-Chun Liu (PaulLiu) wrote: > Hi Salvatore, > > How to reproduce your bug? > > I'm currently using valgrind with the rar file you provided. And found > that there are some unconditional jump based some uninit value. Please > see the attachment [1]. > > After fixing that

Bug#874060: unrar-free: CVE-2017-14122: stack overread vulnerability

2017-10-14 Thread Ying-Chun Liu (PaulLiu)
Hi Salvatore, How to reproduce your bug? I'm currently using valgrind with the rar file you provided. And found that there are some unconditional jump based some uninit value. Please see the attachment [1]. After fixing that [2], valgrind is happy now without any errors. Not sure if this is