openSUSE-SU-2023:0201-1
Dashboard / Vulnerabilities / openSUSE-SU-2023:0201-1
openSUSE-SU-2023:0201-1
Summary: Security update for libredwg
Details: This update for libredwg fixes the following issues: Update to version 0.12.5.5907 Security issues fixed: * CVE-2022-33025: Fixed multiple security issues [boo#1200898] * CVE-2023-36271: Fixed heap buffer overflow via the function bit_wcs2nlen [boo#1212709] * CVE-2023-36272: Fixed heap buffer overflow via the function bit_utf8_to_TU [boo#1212707] * CVE-2023-36273: Fixed heap buffer overflow via the function bit_calc_CRC [boo#1212706] * CVE-2023-36274: Fixed heap buffer overflow via the function bit_write_TF [boo#1212705]
References: https://lists.opensuse.org/archives/list/[email protected]/thread/5EOM2KLYJEVITQUC3RNZBNGK6DL4RR4C/, https://bugzilla.suse.com/1200898, https://bugzilla.suse.com/1212705, https://bugzilla.suse.com/1212706, https://bugzilla.suse.com/1212707, https://bugzilla.suse.com/1212709, https://www.suse.com/security/cve/CVE-2022-33025, https://www.suse.com/security/cve/CVE-2023-36271, https://www.suse.com/security/cve/CVE-2023-36272, https://www.suse.com/security/cve/CVE-2023-36273, https://www.suse.com/security/cve/CVE-2023-36274
Affected packages
Package
Name: libredwg
Purl: pkg:rpm/suse/libredwg&distro=SUSE%20Package%20Hub%2015%20SP5
Affected ranges
Type: ECOSYSTEM
Events:
