A flaw was found in the loadbuf function in formisc.c. When the buffer is too small, the function tries to resize it, but only by Bsize (=128) bytes. This is not necessarily enough and could cause denial of service.
{ "section": "core" }
"https://advisories.mageia.org/MGASA-2017-0392.json"