Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Mageia: 2019-0128 Moderate: Advancecomp Integer Overflow Risk

mageia
Calendar Grey April 5, 2019
Dist Mageia Esm H88
MGASA-2019-0129 provides a patch that resolves memory corruption vulnerabilities and issues linked to JPEG processing.
advancecomp has been updated to fix a security issue that could be triggered when pressented with a malformed PNG file

Summary

advancecomp has been updated to fix a security issue that could be triggered when pressented with a malformed PNG file. advancecomp contained an integer overflow upon encountering an invalid PNG size, which could result in a buffer overflow (CVE-2019-9210), as well as a heap-based buffer over-read.

References

- https://bugs.mageia.org/show_bug.cgi?id=24535

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/DPZCDOUS5QYMW45SCXCDPCWKC4QVMPLU/

- https://www.cve.org/CVERecord?id=CVE-2019-9210

Resolution

SRPMS

- 6/core/advancecomp-1.20-3.3.mga6

Publication date: 05 Apr 2019
URL: https://advisories.mageia.org/MGASA-2019-0128.html
Type: security
CVE: CVE-2019-9210

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here