KiCad could be made to crash or run programs if it opened a specially crafted file.. ========================================================================== Ubuntu Security Notice USN-7466-1 April 28, 2025 kicad vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: KiCad could be made to crash or run programs if it opened a specially crafted file. Software Description: - kicad: Electronic schematic and PCB design software Details: It was discovered that KiCad incorrectly handled memory when opening malicious files. An attacker could possibly use this issue to cause a denial of service or execute arbitrary commands. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS kicad 5.1.5+dfsg1-2ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 18.04 LTS kicad 4.0.7+dfsg1-1ubuntu2+esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7466-1 CVE-2022-23803, CVE-2022-23804, CVE-2022-23946, CVE-2022-23947 . The latest patch for KiCad on Ubuntu rectifies vulnerabilities that might result in unexpected crashes or unauthorized command execution.. KiCad Security Update, Ubuntu Pro, Denial of Service, Memory Issues, Software Security. . LinuxSecurity.com Team
KiCad is a suite of programs for the creation of printed circuit boards. It includes a schematic editor, a PCB layout tool, support tools and a 3D viewer to display a finished & fully populated PCB. . ------------------------------------------------------------------------- Debian LTS Advisory DLA-3078-1
KiCad is a suite of programs for the creation of printed circuit boards. It includes a schematic editor, a PCB layout tool, support tools and a 3D viewer to display a finished & fully populated PCB. . ------------------------------------------------------------------------- Debian LTS Advisory DLA-2998-1
Update to 6.0.2. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-78b18981a6 2022-03-02 16:10:21.012493 --------------------------------------------------------------------------------Name : kicad Product : Fedora 35 Version : 6.0.2 Release : 1.fc35 URL : https://www.kicad.org Summary : EDA software suite for creation of schematic diagrams and PCBs Description : KiCad is EDA software to design electronic schematic diagrams and printed circuit board artwork of up to 32 layers. --------------------------------------------------------------------------------Update Information: Update to 6.0.2 --------------------------------------------------------------------------------ChangeLog: * Fri Feb 11 2022 Steven A. Falco - 1:6.0.2-1 - Update to 6.0.2 * Thu Feb 10 2022 Orion Poplawski - 1:6.0.1-5 - Rebuild for glew 2.2 * Mon Jan 31 2022 Steven A. Falco - 1:6.0.1-4 - Fix conflict in docs * Tue Jan 25 2022 Steven A. Falco - 1:6.0.1-3 - Patch missing include file * Thu Jan 20 2022 Fedora Release Engineering - 1:6.0.1-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild * Wed Jan 12 2022 Steven A. Falco - 1:6.0.1-1 - Update to 6.0.1 * Sat Dec 25 2021 Steven A. Falco - 1:6.0.0-2 - Update cmake flags * Thu Dec 23 2021 Steven A. Falco - 1:6.0.0-1 - Update to 6.0.0 * Tue Nov 16 2021 Steven A. Falco - 1:6.0.0-0.1.rc1 - Update to 6.0.0-rc1 --------------------------------------------------------------------------------References: [ 1 ] Bug #2054957 - CVE-2022-23946 kicad: KiCad 6.0.1 Stack-based buffer overflow in GCodeNumber parsing [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2054957 [ 2 ] Bug #2054960 - CVE-2022-23947 kicad: KiCad 6.0.1 Stack-based buffer overflow in DCodeNumber parsing [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2054960 [ 3 ] Bug #2054974 - CVE-2022-23803 kicad: KiCad 6.0.1Stack-based buffer overflow in ReadXYCoord [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2054974 [ 4 ] Bug #2054980 - CVE-2022-23804 kicad: KiCad 6.0.1 Stack-based buffer overflow in ReadIJCoord [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2054980 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-78b18981a6' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.