PublicDateAtUSN: 2014-12-31 Candidate: CVE-2014-9765 PublicDate: 2016-04-19 21:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9765 http://www.openwall.com/lists/oss-security/2016/02/08/1 https://ubuntu.com/security/notices/USN-2901-1 Description: Buffer overflow in the main_get_appheader function in xdelta3-main.h in xdelta3 before 3.0.9 allows remote attackers to execute arbitrary code via a crafted input file. Ubuntu-Description: Notes: sbeattie> xdelta3 < 3.0.9 Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=814067 Priority: medium Discovered-by: Assigned-to: mdeslaur CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H [8.8 HIGH] Patches_xdelta3: upstream: https://github.com/jmacd/xdelta-devel/commit/ef93ff74203e030073b898c05e8b4860b5d09ef2 upstream_xdelta3: released (3.0.9) precise_xdelta3: released (3.0.0.dfsg-1+deb7u1build0.12.04.1) trusty_xdelta3: released (3.0.7-dfsg-2ubuntu0.2) trusty/esm_xdelta3: DNE (trusty was released [3.0.7-dfsg-2ubuntu0.2]) vivid/stable-phone-overlay_xdelta3: DNE vivid/ubuntu-core_xdelta3: DNE wily_xdelta3: released (3.0.8-dfsg-1ubuntu0.15.10.2) devel_xdelta3: released (3.0.8-dfsg-1ubuntu2)