A vulnerability classified as problematic has been found in MediaArea ZenLib up to 0.4.38. This affects the function Ztring::Date_From_Seconds_1970_Local of the file Source/ZenLib/Ztring.cpp. The manipulation of the argument Value leads to unchecked return value to null pointer dereference. (CVE-2020-36646) . MGASA-2023-0046 - Updated libzen packages fix security vulnerability Publication date: 14 Feb 2023 URL: https://advisories.mageia.org/MGASA-2023-0046.html Type: security Affected Mageia releases: 8 CVE: CVE-2020-36646 A vulnerability classified as problematic has been found in MediaArea ZenLib up to 0.4.38. This affects the function Ztring::Date_From_Seconds_1970_Local of the file Source/ZenLib/Ztring.cpp. The manipulation of the argument Value leads to unchecked return value to null pointer dereference. (CVE-2020-36646) References: - https://bugs.mageia.org/show_bug.cgi?id=31492 - https://lists.debian.org/debian-lts-announce/2023/01/msg00029.html - https://www.cve.org/CVERecord?id=CVE-2020-36646 SRPMS: - 8/core/libzen-0.4.38-1.1.mga8 . A significant security bulletin has been issued for Mageia, highlighting a severe vulnerability within libzen that compromises local date interpretation. Dive into the patch!. Mageia Libzen Security Update, MediaArea Vulnerability, Null Pointer Dereference, Security Issue Mitigation. . Severity: Critical. LinuxSecurity.com Team
Crafted arguments to a function could lead to an unchecked return value and a null pointer dereference. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3290-1
Update mediainfo.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-3b67623d93 2021-04-06 01:03:31.227619 --------------------------------------------------------------------------------Name : libzen Product : Fedora 33 Version : 0.4.39 Release : 1.fc33 URL : https://github.com/MediaArea/ZenLib Summary : Shared library for libmediainfo and medianfo* Description : Files shared library for libmediainfo and medianfo-*. --------------------------------------------------------------------------------Update Information: Update mediainfo. --------------------------------------------------------------------------------ChangeLog: * Sun Mar 28 2021 Vasiliy N. Glazov - 0.4.39-1 - Update to 0.4.39 * Tue Jan 26 2021 Fedora Release Engineering - 0.4.38-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #1940984 - CVE-2020-26797 mediainfo: heap-based buffer overflow via MediaInfoLib::File_Gxf::ChooseParser_ChannelGrouping [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1940984 [ 2 ] Bug #1940986 - CVE-2020-26797 libmediainfo: mediainfo: heap-based buffer overflow via MediaInfoLib::File_Gxf::ChooseParser_ChannelGrouping [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1940986 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-3b67623d93' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.