MGASA-2019-0050

Source
https://advisories.mageia.org/MGASA-2019-0050.html
Import Source
https://advisories.mageia.org/MGASA-2019-0050.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2019-0050
Related
Published
2019-01-23T15:50:09Z
Modified
2019-01-23T15:13:26Z
Summary
Updated libcaca packages fix security vulnerabilities
Details

It was discovered that libcaca incorrectly handled certain images. An attacker could possibly use this issue to cause a denial of service (CVE-2018-20544).

It was discovered that libcaca incorrectly handled certain images. An attacker could possibly use this issue to execute arbitrary code (CVE-2018-20545, CVE-2018-20548, CVE-2018-20459).

It was discovered that libcaca incorrectly handled certain images. An attacker could possibly use this issue to access sensitive information (CVE-2018-20546, CVE-2018-20547).

References
Credits

Affected packages

Mageia:6 / libcaca

Package

Name
libcaca
Purl
pkg:rpm/mageia/libcaca?distro=mageia-6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.99-0.beta18.13.1.mga6

Ecosystem specific

{
    "section": "core"
}