MGASA-2019-0064 - Updated transfig packages fix security vulnerability

Publication date: 13 Feb 2019
URL: https://advisories.mageia.org/MGASA-2019-0064.html
Type: security
Affected Mageia releases: 6
CVE: CVE-2018-16140

It was discovered that transfig incorrectly handled certain FIG files. An
attacker could possibly use this to execute arbitrary code
(CVE-2018-16140).

References:
- https://bugs.mageia.org/show_bug.cgi?id=23537
- https://ubuntu.com/security/notices/USN-3760-1
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-16140

SRPMS:
- 6/core/transfig-3.2.5d-9.2.mga6

Mageia 2019-0064: transfig security update

It was discovered that transfig incorrectly handled certain FIG files

Summary

It was discovered that transfig incorrectly handled certain FIG files. An attacker could possibly use this to execute arbitrary code (CVE-2018-16140).

References

- https://bugs.mageia.org/show_bug.cgi?id=23537

- https://ubuntu.com/security/notices/USN-3760-1

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-16140

Resolution

MGASA-2019-0064 - Updated transfig packages fix security vulnerability

SRPMS

- 6/core/transfig-3.2.5d-9.2.mga6

Severity
Publication date: 13 Feb 2019
URL: https://advisories.mageia.org/MGASA-2019-0064.html
Type: security
CVE: CVE-2018-16140

Related News