Vulnerability Bulletins

DSA-4095 gcab - security update

   
Affected software Debian
 
It was discovered that gcab, a Microsoft Cabinet file manipulation tool,is prone to a stack-based buffer overflow vulnerability when extracting.cab files. An attacker can take advantage of this flaw to cause adenial-of-service or, potentially the execution of arbitrary code withthe privileges of the user running gcab, if a specially crafted .cabfile is processed.

More info:

https://www.debian.org/security/2018/dsa-4095