Debian LTS: DLA-1014-1: libclamunrar security update
Summary
This was caused by an integer overflow resulting in a negative value of the
``DestPos`` variable, which allows the attacker to write out of bounds when
setting ``Mem[DestPos]``.
For Debian 7 "Wheezy", this issue has been fixed in libclamunrar version
0.99-0+deb7u2.
We recommend that you upgrade your libclamunrar packages.
Regards,
- --
,''`.
: :' : Chris Lamb
`. `'` lamby@debian.org / chris-lamb.co.uk
`-