MGASA-2019-0205
Dashboard / Vulnerabilities / MGASA-2019-0205
MGASA-2019-0205
Summary: Updated dosbox package fixes security vulnerabilities
Details: Dosbox 0.74-3 is a security release: * Fixed that a very long line inside a bat file would overflow the parsing buffer. (CVE-2019-7165 by Alexandre Bartel) * Added a basic permission system so that a program running inside DOSBox can't access the contents of /proc (e.g. /proc/self/mem) when / or /proc were (to be) mounted. (CVE-2019-12594 by Alexandre Bartel) It also brings several other fixes for out of bounds access and buffer overflows, and some fixes to the OpenGL rendering. The game compatibility should be identical to 0.74 and 0.74-2. It is recommended to use config -securemode when dealing with untrusted files.
References: https://advisories.mageia.org/MGASA-2019-0205.html, https://bugs.mageia.org/show_bug.cgi?id=25013
Affected packages
Package
Name: dosbox
Purl: pkg:rpm/mageia/dosbox?arch=source&distro=mageia-6
Affected ranges
Type: ECOSYSTEM
Events:
