MGASA-2021-0073 - Updated gdisk package fixes security vulnerabilities

Publication date: 06 Feb 2021
URL: https://advisories.mageia.org/MGASA-2021-0073.html
Type: security
Affected Mageia releases: 7
CVE: CVE-2020-0256,
     CVE-2021-0308

A bug that could cause segfault if GPT header claimed partition entries are
oversized (CVE-2020-0256).

A bug that could cause a crash if a badly-formatted MBR disk was read
(CVE-2021-0308).

The gdisk package has been updated to version 1.0.6, fixing these issues and
several other bugs.  See the upstream NEWS file for details.

References:
- https://bugs.mageia.org/show_bug.cgi?id=28206
- https://sourceforge.net/p/gptfdisk/code/ci/6180deb472c302c47f4d4acff8f2123d10824364/tree/NEWS
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-0256
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-0308

SRPMS:
- 7/core/gdisk-1.0.6-1.mga7

Mageia 2021-0073: gdisk security update

A bug that could cause segfault if GPT header claimed partition entries are oversized (CVE-2020-0256)

Summary

A bug that could cause segfault if GPT header claimed partition entries are oversized (CVE-2020-0256).
A bug that could cause a crash if a badly-formatted MBR disk was read (CVE-2021-0308).
The gdisk package has been updated to version 1.0.6, fixing these issues and several other bugs. See the upstream NEWS file for details.

References

- https://bugs.mageia.org/show_bug.cgi?id=28206

- https://sourceforge.net/p/gptfdisk/code/ci/6180deb472c302c47f4d4acff8f2123d10824364/tree/NEWS

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-0256

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-0308

Resolution

MGASA-2021-0073 - Updated gdisk package fixes security vulnerabilities

SRPMS

- 7/core/gdisk-1.0.6-1.mga7

Severity
Publication date: 06 Feb 2021
URL: https://advisories.mageia.org/MGASA-2021-0073.html
Type: security
CVE: CVE-2020-0256, CVE-2021-0308

Related News