Alerts This Week
Warning Icon 1 923
Alerts This Week
Warning Icon 1 923

Mageia 8: 2023-0102 Moderate: gedit Potential Security Exposure

mageia
Calendar Grey March 18, 2023
Dist Mageia Esm H88
Enhanced xfig software in Mageia resolves a possible buffer overflow issue that might permit arbitrary code execution or result in a Denial of Service.
A potential buffer overflow exists in the file src/w_help.c at line 55

Summary

A potential buffer overflow exists in the file src/w_help.c at line 55. Specifically, the length of the string returned by getenv("LANG") may become very long and cause a buffer overflow while executing the sprintf() function. This vulnerability could potentially allow an attacker to execute arbitrary code or cause a denial-of-service condition. (CVE-2021-40241)

References

- https://bugs.mageia.org/show_bug.cgi?id=31650

- https://lists.debian.org/debian-lts-announce/2023/03/msg00005.html

- https://www.cve.org/CVERecord?id=CVE-2021-40241

Resolution

SRPMS

- 8/core/xfig-3.2.7b-1.1.mga8

Publication date: 18 Mar 2023
URL: https://advisories.mageia.org/MGASA-2023-0101.html
Type: security
CVE: CVE-2021-40241

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here