Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

Mageia: 2021-0550 Moderate: cveengine Memory Corruption Vulnerability

mageia
Calendar Grey December 10, 2021
Dist Mageia Esm H88
Mageia has issued crucial updates for curaengine packages to fix serious buffer overflow vulnerabilities linked to JPEG file processing, protecting user data and system integrity
Buffer overflow vulnerability in function stbi__extend_receive in stb_image.h in stb 2.26 via a crafted JPEG file

Summary

Buffer overflow vulnerability in function stbi__extend_receive in stb_image.h in stb 2.26 via a crafted JPEG file. (CVE-2021-28021)
An issue was discovered in stb stb_image.h 1.33 through 2.27. The HDR loader parsed truncated end-of-file RLE scanlines as an infinite sequence of zero-length runs. An attacker could potentially have caused denial of service in applications using stb_image by submitting crafted HDR files. (CVE-2021-42715)
An issue was discovered in stb stb_image.h 2.27. The PNM loader incorrectly interpreted 16-bit PGM files as 8-bit when converting to RGBA, leading to a buffer overflow when later reinterpreting the result as a 16-bit buffer. An attacker could potentially have crashed a service using stb_image, or read up to 1024 bytes of non-consecutive heap data without control over the read location. (CVE-2021-42716)

References

- https://bugs.mageia.org/show_bug.cgi?id=29622

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/3TDGZFLBOP27LZKLH45WQLSNPSPP7S7Z/

- https://www.cve.org/CVERecord?id=CVE-2021-28021

- https://www.cve.org/CVERecord?id=CVE-2021-42715

- https://www.cve.org/CVERecord?id=CVE-2021-42716

Resolution

SRPMS

- 8/core/curaengine-4.8.0-1.1.mga8

Publication date: 10 Dec 2021
URL: https://advisories.mageia.org/MGASA-2021-0549.html
Type: security
CVE: CVE-2021-28021, CVE-2021-42715, CVE-2021-42716

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here