Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Debian 9 Stretch DLA-2998-1 Moderate: Kicad Buffer Overflow Threats

debian lts
Calendar Grey May 9, 2022
Dist Debian Esm H88
Notice regarding kicad upgrade to resolve buffer overflow vulnerabilities. Immediate update advised for enhanced protection.
KiCad is a suite of programs for the creation of printed circuit boards

Summary

Several buffer-overflows were discovered in the Gerber Viewer and excellon
file parser, that could lead to code execution when opening a
maliciously-crafted file.

CVE-2022-23803

A stack-based buffer overflow vulnerability exists in the Gerber Viewer
gerber and excellon ReadXYCoord coordinate parsing functionality of KiCad
EDA.

CVE-2022-23804

A stack-based buffer overflow vulnerability exists in the Gerber Viewer
gerber and excellon ReadIJCoord coordinate parsing functionality of KiCad
EDA.

CVE-2022-23946

A stack-based buffer overflow vulnerability exists in the Gerber Viewer
gerber and excellon GCodeNumber parsing functionality of KiCad EDA.

CVE-2022-23947

A stack-based buffer overflow vulnerability exists in the Gerber Viewer
gerber and excellon DCodeNumber parsing functionality of KiCad EDA.

For Debian 9 stretch, these problems have been fixed in version
4.0.5+dfsg1-4+deb9u1.

We recommend that you upgrade your kicad packages.

Read the Full Advisory


Severity
important
Lowest
Low
Medium
High
Critical

Package: kicad
Version: 4.0.5+dfsg1-4+deb9u1
CVE ID: CVE-2022-23803 CVE-2022-23804 CVE-2022-23946 CVE-2022-23947

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here