Alerts This Week
Warning Icon 1 681
Alerts This Week
Warning Icon 1 681

Mageia: MGASA-2022-0116 Moderate: abcm2ps DoS Attacks Threat

mageia
Calendar Grey March 24, 2022
Dist Mageia Esm H88
Mageia abcm2ps package security alert responds to DoS and buffer overflow flaws revealed on March 24, 2022.
abcm2ps v8.14.11 was discovered to contain an out-of-bounds read in the function calculate_beam at draw.c

Summary

abcm2ps v8.14.11 was discovered to contain an out-of-bounds read in the function calculate_beam at draw.c. (CVE-2021-32434) Stack-based buffer overflow in the function get_key in parse.c of abcm2ps v8.14.11 allows remote attackers to cause a Denial of Service (DoS) via unspecified vectors. (CVE-2021-32435) An out-of-bounds read in the function write_title() in subs.c of abcm2ps v8.14.11 allows remote attackers to cause a Denial of Service (DoS) via unspecified vectors. (CVE-2021-32436)

References

- https://bugs.mageia.org/show_bug.cgi?id=30195

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/6333SXWMES3K22DBAOAW34G6EU6WIJEY/

- https://www.cve.org/CVERecord?id=CVE-2021-32434

- https://www.cve.org/CVERecord?id=CVE-2021-32435

- https://www.cve.org/CVERecord?id=CVE-2021-32436

Resolution

SRPMS

- 8/core/abcm2ps-8.14.13-1.mga8

Publication date: 24 Mar 2022
URL: https://advisories.mageia.org/MGASA-2022-0116.html
Type: security
CVE: CVE-2021-32434, CVE-2021-32435, CVE-2021-32436

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here