MGASA-2018-0440
Dashboard / Vulnerabilities / MGASA-2018-0440
MGASA-2018-0440
Summary: Updated iniparser packages fix security vulnerability
Details: A flaw was found in iniparser version prior to 4.1. A stack buffer underflow in the function iniparser_load() in iniparser.c file which can be triggered by parsing a file that containing a zero-byte. This vulnerability may allow an attacker to cause a Denial of Service (DoS).
References: https://advisories.mageia.org/MGASA-2018-0440.html, https://bugs.mageia.org/show_bug.cgi?id=23561, https://github.com/ndevilla/iniparser/issues/68, https://bugzilla.redhat.com/show_bug.cgi?id=1545824, https://lists.fedoraproject.org/archives/list/[email protected]/thread/JM5SZJJT2YKW6NSUEDTA7J4RSLYWP37D/
Affected packages
Package
Name: iniparser
Purl: pkg:rpm/mageia/iniparser?arch=source&distro=mageia-6
Affected ranges
Type: ECOSYSTEM
Events:
