PLIB could be made to execute arbitrary code if it opens a specially crafted TGA file.. ========================================================================== Ubuntu Security Notice USN-6353-1 September 07, 2023 plib vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS (Available with Ubuntu Pro) - Ubuntu 16.04 LTS (Available with Ubuntu Pro) Summary: PLIB could be made to execute arbitrary code if it opens a specially crafted TGA file. Software Description: - plib: Portability Libraries: Development package Details: Wooseok Kang discovered that PLIB did not properly manage memory under certain circumstances. If a user were tricked into opening a specially crafted TGA file, an attacker could possibly use this issue to cause applications using PLIB to crash, resulting in a denial of service, or possibly execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS: libplib1 1.8.5-8ubuntu0.20.04.1 Ubuntu 18.04 LTS (Available with Ubuntu Pro): libplib1 1.8.5-8ubuntu0.18.04.1~esm1 Ubuntu 16.04 LTS (Available with Ubuntu Pro): libplib1 1.8.5-7ubuntu0.1~esm1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-6353-1 CVE-2021-38714 Package Information: https://launchpad.net/ubuntu/+source/plib/1.8.5-8ubuntu0.20.04.1 . Critical vulnerability in the networking stack of Fedora enables remote code execution via maliciously designed BMP images. Ensure your system is updated immediately.. Ubuntu Security, PLIB Exploit, Code Execution Risk. . Severity: Important. LinuxSecurity.com Team
Security fix for CVE-2021-38714. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-1cf3c9578f 2022-05-25 01:28:35.280227 --------------------------------------------------------------------------------Name : plib Product : Fedora 34 Version : 1.8.5 Release : 30.fc34 URL : Summary : Set of portable libraries especially useful for games Description : This is a set of OpenSource (LGPL) libraries that will permit programmers to write games and other realtime interactive applications that are 100% portable across a wide range of hardware and operating systems. Here is what you need - it's all free and available with LGPL'ed source code on the web. All of it works well together. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2021-38714 --------------------------------------------------------------------------------ChangeLog: * Fri May 13 2022 Hans de Goede - 1.8.5-30 - Add 3 patches from Debian - Fixes CVE-2021-38714 (rhbz#1997815) * Fri Jan 21 2022 Fedora Release Engineering - 1.8.5-29 - Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild * Fri Jul 23 2021 Fedora Release Engineering - 1.8.5-28 - Rebuilt for https://fedoraproject.org/wiki/Fedora_35_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #1997814 - CVE-2021-38714 plib: integer overflow could lead to arbitrary code execution https://bugzilla.redhat.com/show_bug.cgi?id=1997814 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-1cf3c9578f' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the FedoraProject GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Security fix for CVE-2021-38714. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-bcc0df5180 2022-05-25 01:23:53.566442 --------------------------------------------------------------------------------Name : plib Product : Fedora 35 Version : 1.8.5 Release : 30.fc35 URL : Summary : Set of portable libraries especially useful for games Description : This is a set of OpenSource (LGPL) libraries that will permit programmers to write games and other realtime interactive applications that are 100% portable across a wide range of hardware and operating systems. Here is what you need - it's all free and available with LGPL'ed source code on the web. All of it works well together. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2021-38714 --------------------------------------------------------------------------------ChangeLog: * Fri May 13 2022 Hans de Goede - 1.8.5-30 - Add 3 patches from Debian - Fixes CVE-2021-38714 (rhbz#1997815) * Fri Jan 21 2022 Fedora Release Engineering - 1.8.5-29 - Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #1997814 - CVE-2021-38714 plib: integer overflow could lead to arbitrary code execution https://bugzilla.redhat.com/show_bug.cgi?id=1997814 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-bcc0df5180' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Security fix for CVE-2021-38714. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-08022e9452 2022-05-25 01:03:47.532310 --------------------------------------------------------------------------------Name : plib Product : Fedora 36 Version : 1.8.5 Release : 30.fc36 URL : Summary : Set of portable libraries especially useful for games Description : This is a set of OpenSource (LGPL) libraries that will permit programmers to write games and other realtime interactive applications that are 100% portable across a wide range of hardware and operating systems. Here is what you need - it's all free and available with LGPL'ed source code on the web. All of it works well together. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2021-38714 --------------------------------------------------------------------------------ChangeLog: * Fri May 13 2022 Hans de Goede - 1.8.5-30 - Add 3 patches from Debian - Fixes CVE-2021-38714 (rhbz#1997815) --------------------------------------------------------------------------------References: [ 1 ] Bug #1997814 - CVE-2021-38714 plib: integer overflow could lead to arbitrary code execution https://bugzilla.redhat.com/show_bug.cgi?id=1997814 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-08022e9452' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Integer overflow vulnerability that could result in arbitrary code execution. The vulnerability is found in ssgLoadTGA() function in src/ssg/ssgLoadTGA.cxx file. References: . MGASA-2021-0476 - Updated plib packages fix security vulnerability Publication date: 13 Oct 2021 URL: https://advisories.mageia.org/MGASA-2021-0476.html Type: security Affected Mageia releases: 8 CVE: CVE-2021-38714 Integer overflow vulnerability that could result in arbitrary code execution. The vulnerability is found in ssgLoadTGA() function in src/ssg/ssgLoadTGA.cxx file. References: - https://bugs.mageia.org/show_bug.cgi?id=29528 - https://lists.debian.org/debian-lts-announce/2021/10/msg00000.html - https://www.cve.org/CVERecord?id=CVE-2021-38714 SRPMS: - 8/core/plib-1.8.5-13.1.mga8 . Integer overflow flaw identified in Mageia's plib libraries may permit execution of arbitrary code. Urgent patch needed.. Mageia Security Update, Integer Overflow, Code Execution Risk. . Severity: Critical. LinuxSecurity.com Team
One security issue has been discovered in plib. Integer overflow vulnerability that could result in arbitrary code execution. The vulnerability is found in ssgLoadTGA() function in src/ssg/ssgLoadTGA.cxx file. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2775-1
An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available.. openSUSE Security Update: update for plib ______________________________________________________________________________ Announcement ID: openSUSE-SU-2013:0146-1 Rating: important References: #738207 #787305 Cross-References: CVE-2011-4620 CVE-2012-4552 Affected Products: openSUSE 11.4/standard/i586/patchinfo.11 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update of plib fixed two stack-based buffer overflows. Patch Instructions: To install this openSUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - openSUSE 11.4/standard/i586/patchinfo.11: zypper in -t patch 2012-5 To bring your system up-to-date, use "zypper patch". Package List: - openSUSE 11.4/standard/i586/patchinfo.11 (i586 x86_64): plib-1.8.5-70.1 plib-debuginfo-1.8.5-70.1 plib-debugsource-1.8.5-70.1 plib-devel-1.8.5-70.1 References: https://www.suse.com/security/cve/CVE-2011-4620.html https://www.suse.com/security/cve/CVE-2012-4552.html . The recent release for plib on openSUSE addresses critical stack-related buffer overflow vulnerabilities. Safeguard your system by applying this advisory promptly.. openSUSE Security, Plib Updates, Important Patches. . Severity: Important. LinuxSecurity.com Team
It was discovered that PLIB, a library used by TORCS, contains a buffer overflow in error message processing, which could allow remote attackers to execute arbitrary code. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DSA-2425-1
Get the latest Linux and open source security news straight to your inbox.