MGASA-2019-0133
Dashboard / Vulnerabilities / MGASA-2019-0133
MGASA-2019-0133
Summary: Updated cfitsio packages fix security vulnerability
Details: CVE-2018-3846: Unsafe use of sprintf() can allow a remote unauthenticated attacker to execute arbitrary code CVE-2018-3848: Stack-based buffer overflow in ffghbn() allows for potential code execution CVE-2018-3849: Stack-based buffer overflow in ffghtb() allows for potential code execution
References: https://advisories.mageia.org/MGASA-2019-0133.html, https://bugs.mageia.org/show_bug.cgi?id=24586, https://bugzilla.redhat.com/show_bug.cgi?id=1563915, https://bugzilla.redhat.com/show_bug.cgi?id=1568184, https://bugzilla.redhat.com/show_bug.cgi?id=1568189
Affected packages
Package
Name: cfitsio
Purl: pkg:rpm/mageia/cfitsio?arch=source&distro=mageia-6
Affected ranges
Type: ECOSYSTEM
Events:
