Alerts This Week
Warning Icon 1 659
Alerts This Week
Warning Icon 1 659

Mageia: 2019-0205 Moderate: Fixes for Dosbox DoS Threat Vulnerabilities

mageia
Calendar Grey July 10, 2019
Dist Mageia Esm H88
MGASA-2023-0210 Highlights essential qemu enhancements for security vulnerabilities and supplementary upgrades, dated 18 Oct 2023.
Dosbox 0.74-3 is a security release: * Fixed that a very long line inside a bat file would overflow the parsing buffer

Summary

Dosbox 0.74-3 is a security release: * Fixed that a very long line inside a bat file would overflow the parsing buffer. (CVE-2019-7165 by Alexandre Bartel) * Added a basic permission system so that a program running inside DOSBox can't access the contents of /proc (e.g. /proc/self/mem) when / or /proc were (to be) mounted. (CVE-2019-12594 by Alexandre Bartel)
It also brings several other fixes for out of bounds access and buffer overflows, and some fixes to the OpenGL rendering.
The game compatibility should be identical to 0.74 and 0.74-2. It is recommended to use config -securemode when dealing with untrusted files.

References

- https://bugs.mageia.org/show_bug.cgi?id=25013

- https://www.cve.org/CVERecord?id=CVE-2019-7165

- https://www.cve.org/CVERecord?id=CVE-2019-12594

Resolution

SRPMS

- 7/core/dosbox-0.74.3-1.mga7

- 6/core/dosbox-0.74.3-1.mga6

Publication date: 10 Jul 2019
URL: https://advisories.mageia.org/MGASA-2019-0205.html
Type: security
CVE: CVE-2019-7165, CVE-2019-12594

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here