Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Debian 9 Stretch DLA-2705-1 Critical: Scilab Memory Handling

debian lts
Calendar Grey July 8, 2021
Dist Debian Esm H88
Tackling vital safety concerns in Scilab, particularly memory vulnerabilities, that may result in possible breaches and solutions.
Multiple issues have been discovered in scilab, particularly in ezXML embedded library: CVE-2021-30485

Summary

CVE-2021-30485

Descriptionincorrect memory handling, leading to a NULL pointer dereference
in ezxml_internal_dtd()

CVE-2021-31229

Out-of-bounds write in ezxml_internal_dtd() leading to out-of-bounds write
of a one byte constant

CVE-2021-31347, CVE-2021-31348

incorrect memory handling in ezxml_parse_str() leading to out-of-bounds read

CVE-2021-31598

Out-of-bounds write in ezxml_decode() leading to heap corruption

For Debian 9 stretch, these problems have been fixed in version
5.5.2-4+deb9u1.

We recommend that you upgrade your scilab packages.

For the detailed security status of scilab please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/scilab

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS


Severity
critical
Lowest
Low
Medium
High
Critical

Package: scilab
Version: 5.5.2-4+deb9u1
CVE ID: CVE-2021-30485 CVE-2021-31229 CVE-2021-31347 CVE-2021-31348

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here