Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Mageia: 2019-0404 Security Advisory on Libmirage Buffer Overflow

mageia
Calendar Grey December 24, 2019
Dist Mageia Esm H88
Recent updates to the libmirage library address critical security flaws that allow unauthorized root access through exploitation of buffer overflow vulnerabilities.
Updated libmirage packages fix security vulnerabilities: The CSO filter in libMirage in CDemu did not validate the part size, triggering a heap-based buffer overflow that could le...

Summary

Updated libmirage packages fix security vulnerabilities:
The CSO filter in libMirage in CDemu did not validate the part size, triggering a heap-based buffer overflow that could lead to root access by a local user (CVE-2019-15540).
NULL pointer dereference in the NRG parser (CVE-2019-15757).

References

- https://bugs.mageia.org/show_bug.cgi?id=25762

- https://www.cve.org/CVERecord?id=CVE-2019-15540

- https://www.cve.org/CVERecord?id=CVE-2019-15757

Resolution

SRPMS

- 7/core/libmirage-3.2.3-1.mga7

Severity
important
Lowest
Low
Medium
High
Critical

Publication date: 24 Dec 2019
URL: https://advisories.mageia.org/MGASA-2019-0404.html
Type: security
CVE: CVE-2019-15540, CVE-2019-15757

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here