MGASA-2018-0214
Dashboard / Vulnerabilities / MGASA-2018-0214
MGASA-2018-0214
Summary: Updated libofx packages fix security vulnerabilities
Details: An exploitable buffer overflow vulnerability exists in the tag parsing functionality of LibOFX 0.9.11. A specially crafted OFX file can cause a write out of bounds resulting in a buffer overflow on the stack. An attacker can construct a malicious OFX file to trigger this vulnerability (CVE-2017-2816). An exploitable buffer overflow vulnerability exists in the tag parsing functionality of LibOFX 0.9.11. A specially crafted OFX file can cause a write out of bounds resulting in a buffer overflow on the stack. An attacker can construct a malicious OFX file to trigger this vulnerability (CVE-2017-2920). ofx_proc_file in ofx_preproc.cpp in LibOFX 0.9.12 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file, as demonstrated by an ofxdump call (CVE-2017-14731).
References: https://advisories.mageia.org/MGASA-2018-0214.html, https://bugs.mageia.org/show_bug.cgi?id=22878, https://lists.fedoraproject.org/archives/list/[email protected]/thread/O2W5PV4QMNKEUZEPKO2GNBDRLIDSVDZM/
Affected packages
Package
Name: libofx
Purl: pkg:rpm/mageia/libofx?arch=source&distro=mageia-6
Affected ranges
Type: ECOSYSTEM
Events:
