MGASA-2020-0202 - Updated matio packages fix security vulnerability

Publication date: 08 May 2020
URL: https://advisories.mageia.org/MGASA-2020-0202.html
Type: security
Affected Mageia releases: 7
CVE: CVE-2019-13107

Updated matio packages fix a security vulnerability:

Multiple integer overflows exist in MATIO before 1.5.16, related to
mat.c, mat4.c, mat5.c, mat73.c, and matvar_struct.c (CVE-2019-13107).

The matio package has been updated to version 1.5.16 to fix this issue.

Also:
- The scilab package has been updated to version 6.1.0.
- The java-atk-wrapper package fixes an error (Cannot run program 
  "/opt/X11/bin/xprop") when using java accessibility.
- The jogl2 package fixes a crach with current versions of gallium driver.

References:
- https://bugs.mageia.org/show_bug.cgi?id=26061
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/N7AE25FWDBPC7KLVMPLHT4G64O4GISQQ/
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-13107

SRPMS:
- 7/core/matio-1.5.16-1.mga7
- 7/core/scilab-6.1.0-1.mga7
- 7/core/java-atk-wrapper-0.33.2-5.1.mga7
- 7/core/jogl2-2.3.2-8.1.mga7

Mageia 2020-0202: matio security update

Updated matio packages fix a security vulnerability: Multiple integer overflows exist in MATIO before 1.5.16, related to mat.c, mat4.c, mat5.c, mat73.c, and matvar_struct.c (CVE-2...

Summary

Updated matio packages fix a security vulnerability:
Multiple integer overflows exist in MATIO before 1.5.16, related to mat.c, mat4.c, mat5.c, mat73.c, and matvar_struct.c (CVE-2019-13107).
The matio package has been updated to version 1.5.16 to fix this issue.
Also: - The scilab package has been updated to version 6.1.0. - The java-atk-wrapper package fixes an error (Cannot run program "/opt/X11/bin/xprop") when using java accessibility. - The jogl2 package fixes a crach with current versions of gallium driver.

References

- https://bugs.mageia.org/show_bug.cgi?id=26061

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/N7AE25FWDBPC7KLVMPLHT4G64O4GISQQ/

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-13107

Resolution

MGASA-2020-0202 - Updated matio packages fix security vulnerability

SRPMS

- 7/core/matio-1.5.16-1.mga7

- 7/core/scilab-6.1.0-1.mga7

- 7/core/java-atk-wrapper-0.33.2-5.1.mga7

- 7/core/jogl2-2.3.2-8.1.mga7

Severity
Publication date: 08 May 2020
URL: https://advisories.mageia.org/MGASA-2020-0202.html
Type: security
CVE: CVE-2019-13107

Related News