MGASA-2022-0116
Dashboard / Vulnerabilities / MGASA-2022-0116
MGASA-2022-0116
Summary: Updated abcm2ps packages fix security vulnerability
Details: abcm2ps v8.14.11 was discovered to contain an out-of-bounds read in the function calculate_beam at draw.c. (CVE-2021-32434) Stack-based buffer overflow in the function get_key in parse.c of abcm2ps v8.14.11 allows remote attackers to cause a Denial of Service (DoS) via unspecified vectors. (CVE-2021-32435) An out-of-bounds read in the function write_title() in subs.c of abcm2ps v8.14.11 allows remote attackers to cause a Denial of Service (DoS) via unspecified vectors. (CVE-2021-32436)
References: https://advisories.mageia.org/MGASA-2022-0116.html, https://bugs.mageia.org/show_bug.cgi?id=30195, https://lists.fedoraproject.org/archives/list/[email protected]/thread/6333SXWMES3K22DBAOAW34G6EU6WIJEY/
Affected packages
Package
Name: abcm2ps
Purl: pkg:rpm/mageia/abcm2ps?arch=source&distro=mageia-8
Affected ranges
Type: ECOSYSTEM
Events:
