Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

Mageia 6 - MGASA-2018-0448 Moderate: NULL Pointer And Double-Free Flaws

mageia
Calendar Grey November 15, 2018
Dist Mageia Esm H88
The MGASA-2018-0449 patch release resolves severe buffer overflow and memory leak vulnerabilities that might cause instability in the application.
A NULL pointer dereference flaw was found in the way patch processed patch files

Summary

A NULL pointer dereference flaw was found in the way patch processed patch files. An attacker could potentially use this flaw to crash patch by tricking it into processing crafted patches (CVE-2018-6951).
A double-free flaw was found in the way the patch utility processed patch files. An attacker could potentially use this flaw to crash the patch utility by tricking it into processing crafted patches (CVE-2018-6952).

References

- https://bugs.mageia.org/show_bug.cgi?id=23704

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/DTAZPKCAJTAOK6CYQP7SPWNXDIAG4A37/

- https://www.cve.org/CVERecord?id=CVE-2018-6951

- https://www.cve.org/CVERecord?id=CVE-2018-6952

Resolution

SRPMS

- 6/core/patch-2.7.6-1.1.mga6

Publication date: 15 Nov 2018
URL: https://advisories.mageia.org/MGASA-2018-0448.html
Type: security
CVE: CVE-2018-6951, CVE-2018-6952

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here