- ------------------------------------------------------------------------- Debian LTS Advisory DLA-2705-1 [email protected] https://www.debian.org/lts/security/ Anton Gladky July 07, 2021 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : scilab Version : 5.5.2-4+deb9u1 CVE ID : CVE-2021-30485 CVE-2021-31229 CVE-2021-31347 CVE-2021-31348 CVE-2021-31598 Multiple issues have been discovered in scilab, particularly in ezXML embedded library: CVE-2021-30485 Descriptionincorrect memory handling, leading to a NULL pointer dereference in ezxml_internal_dtd() CVE-2021-31229 Out-of-bounds write in ezxml_internal_dtd() leading to out-of-bounds write of a one byte constant CVE-2021-31347, CVE-2021-31348 incorrect memory handling in ezxml_parse_str() leading to out-of-bounds read CVE-2021-31598 Out-of-bounds write in ezxml_decode() leading to heap corruption For Debian 9 stretch, these problems have been fixed in version 5.5.2-4+deb9u1. We recommend that you upgrade your scilab packages. For the detailed security status of scilab please refer to its security tracker page at: https://security-tracker.debian.org/tracker/scilab Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS