LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Slackware
User Name
Password
Slackware This Forum is for the discussion of Slackware Linux.

Notices


Reply
  Search this Thread
Old 06-29-2022, 06:10 AM   #1
Nobby6
Member
 
Registered: Jul 2012
Location: Sunshine Coast, Australia
Distribution: Slackware 64
Posts: 237
Blog Entries: 1

Rep: Reputation: 212Reputation: 212Reputation: 212
UNRAR Vulnerability


https://blog.sonarsource.com/zimbra-...ia-unrar-0day/

Software and versions affected
In this section we go into detail about which versions of unrar are affected. Although this blog post focuses on Zimbra to demonstrate the impact of this bug, any software relying on an unpatched version of unrar to extract untrusted archives is affected.
 
Old 06-29-2022, 08:42 AM   #2
rkelsen
Senior Member
 
Registered: Sep 2004
Distribution: slackware
Posts: 4,463
Blog Entries: 7

Rep: Reputation: 2561Reputation: 2561Reputation: 2561Reputation: 2561Reputation: 2561Reputation: 2561Reputation: 2561Reputation: 2561Reputation: 2561Reputation: 2561Reputation: 2561
Thanks for letting us know. But what does it have to do with Slackware?
 
Old 06-29-2022, 10:02 AM   #3
BenCollver
Rogue Class
 
Registered: Sep 2006
Location: OR, USA
Distribution: Slackware64-15.0
Posts: 376
Blog Entries: 2

Rep: Reputation: 172Reputation: 172
https://slackbuilds.org/repository/15.0/system/unrar/

Version 5.6.1 on slackbuilds.org is vulnerable
 
3 members found this post helpful.
Old 06-29-2022, 10:06 AM   #4
ponce
LQ Guru
 
Registered: Aug 2004
Location: Pisa, Italy
Distribution: Slackware
Posts: 7,113

Rep: Reputation: 4185Reputation: 4185Reputation: 4185Reputation: 4185Reputation: 4185Reputation: 4185Reputation: 4185Reputation: 4185Reputation: 4185Reputation: 4185Reputation: 4185
Quote:
Originally Posted by BenCollver View Post
https://slackbuilds.org/repository/15.0/system/unrar/

Version 5.6.1 on slackbuilds.org is vulnerable
https://git.slackbuilds.org/slackbui...it/?id=16d3c0e
 
6 members found this post helpful.
Old 06-29-2022, 03:59 PM   #5
rkelsen
Senior Member
 
Registered: Sep 2004
Distribution: slackware
Posts: 4,463
Blog Entries: 7

Rep: Reputation: 2561Reputation: 2561Reputation: 2561Reputation: 2561Reputation: 2561Reputation: 2561Reputation: 2561Reputation: 2561Reputation: 2561Reputation: 2561Reputation: 2561
Quote:
Originally Posted by BenCollver View Post
https://slackbuilds.org/repository/15.0/system/unrar/

Version 5.6.1 on slackbuilds.org is vulnerable
That makes it a Slackbuilds problem, not a Slackware problem.

There are mechanisms for reporting such things: https://slackbuilds.org/bugs/
 
Old 06-29-2022, 04:18 PM   #6
pchristy
Senior Member
 
Registered: Oct 2012
Location: South Devon, UK
Distribution: Slackware
Posts: 1,120

Rep: Reputation: Disabled
Quote:
Originally Posted by rkelsen View Post
That makes it a Slackbuilds problem, not a Slackware problem.
You're not wrong, but users need to be made aware - and this is probably one of the best places to do it.

--
Pete
 
6 members found this post helpful.
Old 06-29-2022, 08:02 PM   #7
rkelsen
Senior Member
 
Registered: Sep 2004
Distribution: slackware
Posts: 4,463
Blog Entries: 7

Rep: Reputation: 2561Reputation: 2561Reputation: 2561Reputation: 2561Reputation: 2561Reputation: 2561Reputation: 2561Reputation: 2561Reputation: 2561Reputation: 2561Reputation: 2561
Quote:
Originally Posted by pchristy View Post
You're not wrong, but users need to be made aware - and this is probably one of the best places to do it.
That being the case, wouldn't it get better exposure in the "Linux - Software" part of the forum?
 
Old 06-30-2022, 01:54 AM   #8
pchristy
Senior Member
 
Registered: Oct 2012
Location: South Devon, UK
Distribution: Slackware
Posts: 1,120

Rep: Reputation: Disabled
Possibly, but how many of us go there too? I tend to concentrate on my main areas of interest, basically Slackware and its ARM derivatives. I can't remember when I last visited "Linux - Software", whereas I visit here regularly. Had it not been for the original post here, I would have been blissfully ignorant of this vulnerability. I suspect there are quite a few others like me.

--
Pete
 
5 members found this post helpful.
Old 06-30-2022, 03:25 AM   #9
Nobby6
Member
 
Registered: Jul 2012
Location: Sunshine Coast, Australia
Distribution: Slackware 64
Posts: 237

Original Poster
Blog Entries: 1

Rep: Reputation: 212Reputation: 212Reputation: 212
Quote:
Originally Posted by rkelsen View Post
Thanks for letting us know. But what does it have to do with Slackware?
really? Im not here to educate you

Last edited by Nobby6; 06-30-2022 at 03:27 AM.
 
2 members found this post helpful.
Old 06-30-2022, 03:44 AM   #10
Nobby6
Member
 
Registered: Jul 2012
Location: Sunshine Coast, Australia
Distribution: Slackware 64
Posts: 237

Original Poster
Blog Entries: 1

Rep: Reputation: 212Reputation: 212Reputation: 212
Quote:
Originally Posted by ponce View Post
Thanks for your speedy work as always ponce..

(I guess it'll be on ftp mirrors too, soon? - our rsync mirror shows old stuff still)

Cheers
 
Old 06-30-2022, 03:53 AM   #11
ponce
LQ Guru
 
Registered: Aug 2004
Location: Pisa, Italy
Distribution: Slackware
Posts: 7,113

Rep: Reputation: 4185Reputation: 4185Reputation: 4185Reputation: 4185Reputation: 4185Reputation: 4185Reputation: 4185Reputation: 4185Reputation: 4185Reputation: 4185Reputation: 4185
Quote:
Originally Posted by Nobby6 View Post
Thanks for your speedy work as always ponce..

(I guess it'll be on ftp mirrors too, soon? - our rsync mirror shows old stuff still)

Cheers
it won't go in the main repository until the next global update, probably in the weekend.

thanks for the report but for the next time, if you have to point out security issues with stuff on SBo, I suggest you to report them to the respective script maintainers and to the slackbuilds-users mailing list: if you report them here on the forum interested people might not read and they might won't get fixed.
this time it has been handled because I happened to incidentally read the post, but don't count on it.

Quote:
Originally Posted by rkelsen View Post
There are mechanisms for reporting such things: https://slackbuilds.org/bugs/
this ---^

Last edited by ponce; 06-30-2022 at 03:57 AM.
 
3 members found this post helpful.
Old 06-30-2022, 08:41 AM   #12
pm_a_cup_of_tea
Member
 
Registered: May 2021
Posts: 58

Rep: Reputation: Disabled
Quote:
Originally Posted by rkelsen View Post
That makes it a Slackbuilds problem, not a Slackware problem.
I appreciated this information. I would not have known otherwise.
 
2 members found this post helpful.
Old 06-30-2022, 09:07 AM   #13
rkelsen
Senior Member
 
Registered: Sep 2004
Distribution: slackware
Posts: 4,463
Blog Entries: 7

Rep: Reputation: 2561Reputation: 2561Reputation: 2561Reputation: 2561Reputation: 2561Reputation: 2561Reputation: 2561Reputation: 2561Reputation: 2561Reputation: 2561Reputation: 2561
Quote:
Originally Posted by pm_a_cup_of_tea View Post
I appreciated this information. I would not have known otherwise.
You would have found out by checking for updates in sbopkg.

Anyhow TIL people still use rar. I don't encounter it much these days. Same goes for arj.
 
Old 06-30-2022, 09:52 AM   #14
Gerard Lally
Senior Member
 
Registered: Sep 2009
Location: Leinster, IE
Distribution: Slackware, NetBSD
Posts: 2,184

Rep: Reputation: 1765Reputation: 1765Reputation: 1765Reputation: 1765Reputation: 1765Reputation: 1765Reputation: 1765Reputation: 1765Reputation: 1765Reputation: 1765Reputation: 1765
Quote:
Originally Posted by rkelsen View Post
You would have found out by checking for updates in sbopkg.

Anyhow TIL people still use rar. I don't encounter it much these days. Same goes for arj.
One of RAR's killer features is its recovery function. I once created a test archive with a recovery record of something like 5 or 10 percent. I was able to damage multiple non-contiguous areas of the archive, using a hex editor, and RAR was able to recover the original archive.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
How to update Security Vulnerability on Rhel Linux (CVE Vulnerability) taufikrizkir Linux - Security 2 05-18-2020 06:11 AM
vulnerability scanning using NMAP on CVE-2014-0322 vulnerability,check vulnerable meeiyoke Linux - Security 2 06-06-2014 05:09 PM
vulnerability scanning using NMAP on CVE-2014-0322 vulnerability,check vulnerable . meeiyoke Linux - Newbie 1 06-06-2014 12:14 PM
Unrar 3.x for Slackware 3.5 Brett-NZ Linux - Newbie 0 10-07-2003 10:56 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Slackware

All times are GMT -5. The time now is 01:51 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration