Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Mageia 8: 2022-0456 Urgent: OpenSSL Buffer Overflow Vulnerability

mageia
Calendar Grey June 8, 2021
Dist Mageia Esm H88
Revised cgal software components mitigated buffer overflow risks to bolster Mageia safety.
Updated cgal packages fix security vulnerabilities: An oob read vulnerability exists in Nef_2/PM_io_parser.h PM_io_parser::read_vertex() Face_of[] OOB read

Summary

Updated cgal packages fix security vulnerabilities:
An oob read vulnerability exists in Nef_2/PM_io_parser.h PM_io_parser::read_vertex() Face_of[] OOB read. An attacker can provide malicious input to trigger this vulnerability (CVE-2020-28601).
An oob read vulnerability exists in Nef_S2/SNC_io_parser.h SNC_io_parser::read_sloop() slh->twin() An attacker can provide malicious input to trigger this vulnerability (CVE-2020-28636).
An oob read vulnerability exists in Nef_S2/SNC_io_parser.h SNC_io_parser::read_sloop() slh->incident_sface. An attacker can provide malicious input to trigger this vulnerability (CVE-2020-35628).
An oob read vulnerability exists in Nef_S2/SNC_io_parser.h SNC_io_parser::read_sface() sfh->volume(). An attacker can provide malicious input to trigger this vulnerability (CVE-2020-35636).

References

- https://bugs.mageia.org/show_bug.cgi?id=28881

- https://lists.debian.org/debian-lts-announce/2021/05/msg00002.html

- https://www.cve.org/CVERecord?id=CVE-2020-28601

- https://www.cve.org/CVERecord?id=CVE-2020-28636

- https://www.cve.org/CVERecord?id=CVE-2020-35628

- https://www.cve.org/CVERecord?id=CVE-2020-35636

Resolution

SRPMS

- 7/core/cgal-4.14-1.1.mga7

Severity
important
Lowest
Low
Medium
High
Critical

Publication date: 08 Jun 2021
URL: https://advisories.mageia.org/MGASA-2021-0238.html
Type: security
CVE: CVE-2020-28601, CVE-2020-28636, CVE-2020-35628, CVE-2020-35636

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here