MGASA-2022-0295
Dashboard / Vulnerabilities / MGASA-2022-0295
MGASA-2022-0295
Summary: Updated kicad packages fix security vulnerability
Details: Multiple buffer overflows were discovered in Kicad, a suite of programs for the creation of printed circuit boards, which could result in the execution of arbitrary code if malformed Gerber/Excellon files, as follows. A stack-based buffer overflow vulnerability exists in the Gerber Viewer gerber and excellon ReadXYCoord coordinate parsing functionality of KiCad EDA 6.0.1 and master commit de006fc010. A specially-crafted gerber or excellon file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability. (CVE-2022-23803) A stack-based buffer overflow vulnerability exists in the Gerber Viewer gerber and excellon ReadIJCoord coordinate parsing functionality of KiCad EDA 6.0.1 and master commit de006fc010. A specially-crafted gerber or excellon file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability. (CVE-2022-23804) A stack-based buffer overflow vulnerability exists in the Gerber Viewer gerber and excellon GCodeNumber parsing functionality of KiCad EDA 6.0.1 and master commit de006fc010. A specially-crafted gerber or excellon file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability. (CVE-2022-23946) A stack-based buffer overflow vulnerability exists in the Gerber Viewer gerber and excellon DCodeNumber parsing functionality of KiCad EDA 6.0.1 and master commit de006fc010. A specially-crafted gerber or excellon file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability. (CVE-2022-23947)
References: https://advisories.mageia.org/MGASA-2022-0295.html, https://bugs.mageia.org/show_bug.cgi?id=30109, https://lists.fedoraproject.org/archives/list/[email protected]/thread/5EMCGSSP3FIWCSL2KXVXLF35JYZKZE5Q/, https://www.debian.org/lts/security/2022/dla-2998, https://www.kicad.org/blog/2022/07/KiCad-6.0.7-Release/, https://www.debian.org/security/2022/dsa-5214
Affected packages
Package
Name: kicad
Purl: pkg:rpm/mageia/kicad?arch=source&distro=mageia-8
Affected ranges
Type: ECOSYSTEM
Events:
