William Khem-Marquez discovered that Pymatgen, a Python library for materials analysis, could be tricked into running arbitrary code if a malformed CIF file is processed. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5763-1
It was discovered that missing input sanitising in the Atril document viewer could result in writing arbitrary files in the users home directory if a malformed epub document is opened. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5688-1
Fixes heap use-after-free when parsing malformed file (upstream issue [2989](. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-e84e1aaa2c 2021-01-31 01:21:54.388482 --------------------------------------------------------------------------------Name : libebml Product : Fedora 33 Version : 1.4.1 Release : 1.fc33 URL : https://www.matroska.org/index.html Summary : Extensible Binary Meta Language library Description : Extensible Binary Meta Language access library A library for reading and writing files with the Extensible Binary Meta Language, a binary pendant to XML. --------------------------------------------------------------------------------Update Information: Fixes heap use-after-free when parsing malformed file (upstream issue [2989](). --------------------------------------------------------------------------------ChangeLog: * Mon Jan 25 2021 Dominik Mierzejewski - 1.4.1-1 - update to 1.4.1 (#1912485) - fixes heap use-after-free when parsing malformed file ( --------------------------------------------------------------------------------References: [ 1 ] Bug #1912485 - libebml-1.4.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=1912485 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-e84e1aaa2c' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
A buffer overflow was found in file, a file type classification tool, which may result in denial of service or potentially the execution of arbitrary code if a malformed CDF (Composite Document File) file is processed. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4550-1
Lilith of Cisco Talos discovered a buffer overflow flaw in the quota code used by e2fsck from the ext2/ext3/ext4 file system utilities. Running e2fsck on a malformed file system can result in the execution of . Package : e2fsprogs Version : 1.42.12-2+deb8u1 CVE ID : CVE-2019-5094 Lilith of Cisco Talos discovered a buffer overflow flaw in the quota code used by e2fsck from the ext2/ext3/ext4 file system utilities. Running e2fsck on a malformed file system can result in the execution of arbitrary code. For Debian 8 "Jessie", this problem has been fixed in version 1.42.12-2+deb8u1. We recommend that you upgrade your e2fsprogs packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . A significant security flaw in e2fsprogs identified by Cisco Talos requires urgent action from Debian users.. Debian Security Update, e2fsprogs Patch, Buffer Overflow Risk, Debian LTS. . Severity: Critical. LinuxSecurity.com Team
William Robinet and Michal Zalewski discovered multiple vulnerabilities in the TIFF library and its tools, which may result in denial of service or the execution of arbitrary code if a malformed TIFF file is processed. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DSA-3273-1
Get the latest Linux and open source security news straight to your inbox.