Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Debian 10 Buster: DLA-3974-1 Elevated: Libpng Memory Leak

debian lts
Calendar Grey April 14, 2022
Dist Debian Esm H88
Debian LTS resolves fribidi vulnerabilities, patching critical buffer overflows and segmentation faults. Immediate updates recommended.
Several issues have been found in fribidi, a free Implementation of the Unicode BiDi algorithm

Summary

Several issues have been found in fribidi, a free Implementation of the
Unicode BiDi algorithm. The issues are related to stack-buffer-overflow,
heap-buffer-overflow, and a SEGV.

CVE-2022-25308
stack-buffer-overflow issue in main()

CVE-2022-25309
heap-buffer-overflow issue in fribidi_cap_rtl_to_unicode()

CVE-2022-25310
SEGV issue in fribidi_remove_bidi_marks()


For Debian 9 stretch, these problems have been fixed in version
0.19.7-1+deb9u2.

We recommend that you upgrade your fribidi packages.

For the detailed security status of fribidi please refer to
its security tracker page at:


Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS



Severity
important
Lowest
Low
Medium
High
Critical

Package: fribidi
Version: 0.19.7-1+deb9u2
CVE ID: CVE-2022-25308 CVE-2022-25309 CVE-2022-25310

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here