MGASA-2022-0465 - Updated matio packages fix security vulnerability

Publication date: 13 Dec 2022
URL: https://advisories.mageia.org/MGASA-2022-0465.html
Type: security
Affected Mageia releases: 8
CVE: CVE-2020-36428,
     CVE-2021-36977

matio (aka MAT File I/O Library) 1.5.18 through 1.5.21 has a heap-based
buffer overflow in ReadInt32DataDouble (called from ReadInt32Data and
Mat_VarRead4). (CVE-2020-36428)

matio (aka MAT File I/O Library) 1.5.20 and 1.5.21 has a heap-based
buffer overflow in H5MM_memcpy (called from H5MM_malloc and
H5C_load_entry), related to use of HDF5 1.12.0. (CVE-2021-36977)

References:
- https://bugs.mageia.org/show_bug.cgi?id=31246
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/DWEPRACQNMJHSGWUZQ5LKNVGWSZ6FMCB/
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-36428
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-36977

SRPMS:
- 8/core/matio-1.5.23-1.mga8

Mageia 2022-0465: matio security update

matio (aka MAT File I/O Library) 1.5.18 through 1.5.21 has a heap-based buffer overflow in ReadInt32DataDouble (called from ReadInt32Data and Mat_VarRead4)

Summary

matio (aka MAT File I/O Library) 1.5.18 through 1.5.21 has a heap-based buffer overflow in ReadInt32DataDouble (called from ReadInt32Data and Mat_VarRead4). (CVE-2020-36428)
matio (aka MAT File I/O Library) 1.5.20 and 1.5.21 has a heap-based buffer overflow in H5MM_memcpy (called from H5MM_malloc and H5C_load_entry), related to use of HDF5 1.12.0. (CVE-2021-36977)

References

- https://bugs.mageia.org/show_bug.cgi?id=31246

- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/DWEPRACQNMJHSGWUZQ5LKNVGWSZ6FMCB/

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-36428

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-36977

Resolution

MGASA-2022-0465 - Updated matio packages fix security vulnerability

SRPMS

- 8/core/matio-1.5.23-1.mga8

Severity
Publication date: 13 Dec 2022
URL: https://advisories.mageia.org/MGASA-2022-0465.html
Type: security
CVE: CVE-2020-36428, CVE-2021-36977

Related News