Alerts This Week
Warning Icon 1 681
Alerts This Week
Warning Icon 1 681

Mageia 7 MGASA-2020-0398 Critical: Libuv Buffer Overflow

mageia
Calendar Grey November 8, 2020
Dist Mageia Esm H88
Mageia 2020-0399 provides essential OpenSSL patch to address critical vulnerability linked to improper input validation on affected installations.
The implementation of realpath in libuv before 1.39 incorrectly determined the buffer size which can result in a buffer overflow if the resolved path is longer than 256 bytes (CVE-...

Summary

The implementation of realpath in libuv before 1.39 incorrectly determined the buffer size which can result in a buffer overflow if the resolved path is longer than 256 bytes (CVE-2020-8252).

References

- https://bugs.mageia.org/show_bug.cgi?id=27403

- https://ubuntu.com/security/notices/USN-4548-1

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/GRACEATF77QULUT3WY4JG54X5ZI4OUWO/

- https://www.cve.org/CVERecord?id=CVE-2020-8252

Resolution

SRPMS

- 7/core/libuv-1.34.2-1.1.mga7

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 08 Nov 2020
URL: https://advisories.mageia.org/MGASA-2020-0398.html
Type: security
CVE: CVE-2020-8252

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here