Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Mageia 8: 2022-0138 Moderate: Libxml2 XML Parsing Vulnerabilities and SEGV

mageia
Calendar Grey April 9, 2022
Dist Mageia Esm H88
Recent fribidi package updates tackle significant security vulnerabilities in Mageia 8. Discover the details surrounding these threats and the implemented solutions.
Stack based buffer overflow

Summary

Stack based buffer overflow. (CVE-2022-25308) Heap-buffer-overflow in fribidi_cap_rtl_to_unicode. (CVE-2022-25309) SEGV in fribidi_remove_bidi_marks. (CVE-2022-25310)

References

- https://bugs.mageia.org/show_bug.cgi?id=30249

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/KXPSWMHAII3BETNRQAOH2TQ7ZPJAMEDT/

- https://www.cve.org/CVERecord?id=CVE-2022-25308

- https://www.cve.org/CVERecord?id=CVE-2022-25309

- https://www.cve.org/CVERecord?id=CVE-2022-25310

Resolution

SRPMS

- 8/core/fribidi-1.0.10-1.1.mga8

Publication date: 09 Apr 2022
URL: https://advisories.mageia.org/MGASA-2022-0136.html
Type: security
CVE: CVE-2022-25308, CVE-2022-25309, CVE-2022-25310

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here