Red Hat Bugzilla – Bug 1234887
CVE-2015-4646 squashfs-tools: stack overflow in read_fragment_table_4 due to fix for CVE-2015-4645
Last modified: 2016-01-22 07:31:08 EST
After applying CVE-2015-4645 fix, squashfs-tools become vulnerable to stack overflow issue - the stack VLA allocation of fragment_table_index[] can easily exceed RLIMIT_STACK. Upstream bug report: https://github.com/devttys0/sasquatch/pull/5 Upstream fix: https://github.com/gcanalesb/sasquatch/commit/6777e08cc38bc780d27c69c1d8c272867b74524f
Created squashfs-tools tracking bugs for this issue: Affects: fedora-all [bug 1234888]