Alerts This Week
Warning Icon 1 700
Alerts This Week
Warning Icon 1 700

Mageia: 2018-0440 Critical Update for iniparser Denial of Service

mageia
Calendar Grey November 11, 2018
Dist Mageia Esm H88
The latest Mageia iniparser updates resolve a significant Denial of Service vulnerability impacting all versions earlier than 4.1, which was made available on 11 November 2018.
A flaw was found in iniparser version prior to 4.1

Summary

A flaw was found in iniparser version prior to 4.1. A stack buffer underflow in the function iniparser_load() in iniparser.c file which can be triggered by parsing a file that containing a zero-byte. This vulnerability may allow an attacker to cause a Denial of Service (DoS).

References

- https://bugs.mageia.org/show_bug.cgi?id=23561

- https://github.com/ndevilla/iniparser/issues/68

- https://bugzilla.redhat.com/show_bug.cgi?id=1545824

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/JM5SZJJT2YKW6NSUEDTA7J4RSLYWP37D/

Resolution

SRPMS

- 6/core/iniparser-3.1-8.mga6

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 11 Nov 2018
URL: https://advisories.mageia.org/MGASA-2018-0440.html
Type: security

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here