MGASA-2017-0426
Dashboard / Vulnerabilities / MGASA-2017-0426
MGASA-2017-0426
Summary: Updated bchunk package fixes security vulnerabilities
Details: bchunk (related to BinChunker) 1.2.0 and 1.2.1 is vulnerable to a heap-based buffer overflow and crash when processing a malformed CUE (.cue) file. (CVE-2017-15953) bchunk (related to BinChunker) 1.2.0 and 1.2.1 is vulnerable to a heap-based buffer overflow (with a resultant invalid free) and crash when processing a malformed CUE (.cue) file. (CVE-2017-15954) bchunk (related to BinChunker) 1.2.0 and 1.2.1 is vulnerable to an "Access violation near NULL on destination operand" and crash when processing a malformed CUE (.cue) file. (CVE-2017-15955)
References: https://advisories.mageia.org/MGASA-2017-0426.html, https://bugs.mageia.org/show_bug.cgi?id=22004, https://www.debian.org/security/2017/dsa-4026
Affected packages
Package
Name: bchunk
Purl: pkg:rpm/mageia/bchunk?arch=source&distro=mageia-5
Affected ranges
Type: ECOSYSTEM
Events:
