Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

Debian 8 Jessie: DLA-1060-1 Critical: libgcrypt Integer Overflow Issue

debian lts
Calendar Grey August 12, 2017
Dist Debian Esm H88
A specifically-designed payload may result in an external denial of service due to a NULL reference vulnerability in libgxps. Update suggested.
It was discovered that there was a NULL pointer dereference in libgxps, a library to handle XML Paper Specification specifications

Summary

Specially-crafted input could lead to a remote denial of service attack.

For Debian 7 "Wheezy", this issue has been fixed in libgxps version
0.2.2-2+deb7u1.

We recommend that you upgrade your libgxps packages.


Regards,

- --
,'`.
: :' : Chris Lamb
`. `'` lamby@debian.org / chris-lamb.co.uk
`-



Severity
critical
Lowest
Low
Medium
High
Critical

Package: libgxps
Version: 0.2.2-2+deb7u1
CVE ID: CVE-2017-11590
Debian Bug: #870183

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here