Candidate: CVE-2015-4646 PublicDate: 2017-04-13 17:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-4646 http://www.openwall.com/lists/oss-security/2015/06/18/10 Description: (1) unsquash-1.c, (2) unsquash-2.c, (3) unsquash-3.c, and (4) unsquash-4.c in Squashfs and sasquatch allow remote attackers to cause a denial of service (application crash) via a crafted input. Ubuntu-Description: Notes: amurray> xenial got updated to 1:4.3-3ubuntu2.16.04.3 fixing this (LP: #1785499) Bugs: Priority: low Discovered-by: Giancarlo Canales Barreto Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H [7.5 HIGH] Patches_squashfs-tools: upstream_squashfs-tools: released (1:4.3-2) precise_squashfs-tools: ignored (reached end-of-life) precise/esm_squashfs-tools: DNE (precise was needed) trusty_squashfs-tools: ignored (reached end-of-life) trusty/esm_squashfs-tools: DNE (trusty was needed) utopic_squashfs-tools: ignored (reached end-of-life) vivid_squashfs-tools: ignored (reached end-of-life) vivid/stable-phone-overlay_squashfs-tools: DNE vivid/ubuntu-core_squashfs-tools: ignored (reached end-of-life) wily_squashfs-tools: ignored (reached end-of-life) xenial_squashfs-tools: not-affected (1:4.3-3) esm-infra/xenial_squashfs-tools: not-affected (1:4.3-3) yakkety_squashfs-tools: ignored (reached end-of-life) zesty_squashfs-tools: ignored (reached end-of-life) artful_squashfs-tools: ignored (reached end-of-life) bionic_squashfs-tools: not-affected (1:4.3-3) cosmic_squashfs-tools: not-affected (1:4.3-3) disco_squashfs-tools: not-affected (1:4.3-3) devel_squashfs-tools: not-affected (1:4.3-3)