MGASA-2021-0476 - Updated plib packages fix security vulnerability

Publication date: 13 Oct 2021
URL: https://advisories.mageia.org/MGASA-2021-0476.html
Type: security
Affected Mageia releases: 8
CVE: CVE-2021-38714

Integer overflow vulnerability that could result in arbitrary code execution.
The vulnerability is found in ssgLoadTGA() function in src/ssg/ssgLoadTGA.cxx
file.

References:
- https://bugs.mageia.org/show_bug.cgi?id=29528
- https://www.debian.org/lts/security/2021/dla-2775
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-38714

SRPMS:
- 8/core/plib-1.8.5-13.1.mga8

Mageia 2021-0476: plib security update

Integer overflow vulnerability that could result in arbitrary code execution

Summary

Integer overflow vulnerability that could result in arbitrary code execution. The vulnerability is found in ssgLoadTGA() function in src/ssg/ssgLoadTGA.cxx file.

References

- https://bugs.mageia.org/show_bug.cgi?id=29528

- https://www.debian.org/lts/security/2021/dla-2775

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-38714

Resolution

MGASA-2021-0476 - Updated plib packages fix security vulnerability

SRPMS

- 8/core/plib-1.8.5-13.1.mga8

Severity
Publication date: 13 Oct 2021
URL: https://advisories.mageia.org/MGASA-2021-0476.html
Type: security
CVE: CVE-2021-38714

Related News