MGASA-2014-0533
Dashboard / Vulnerabilities / MGASA-2014-0533
Summary: Updated unrtf package fixes security vulnerabilities
Details: Updated unrtf package fixes security vulnerabilities: Michal Zalewski reported an out-of-bounds memory access vulnerability in unrtf. Processing a malformed RTF file could lead to a segfault while accessing a pointer that may be under the attacker's control. This would lead to a denial of service (application crash) or, potentially, the execution of arbitrary code (CVE-2014-9274). Hanno Böck also reported a number of other crashes in unrtf (CVE-2014-9275).
References: https://advisories.mageia.org/MGASA-2014-0533.html, https://bugs.mageia.org/show_bug.cgi?id=14783, https://bugzilla.redhat.com/show_bug.cgi?id=1170233
Affected packages
Package
Name: unrtf
Purl: pkg:rpm/mageia/unrtf?arch=source&distro=mageia-4
Affected ranges
Type: ECOSYSTEM
Events:
