MGASA-2019-0404

Source
https://advisories.mageia.org/MGASA-2019-0404.html
Import Source
https://advisories.mageia.org/MGASA-2019-0404.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2019-0404
Related
  • CVE-2019-15540
  • CVE-2019-15757
Published
2019-12-24T12:24:34Z
Modified
2019-12-24T12:03:58Z
Summary
Updated libmirage packages fix security vulnerabilities
Details

Updated libmirage packages fix security vulnerabilities:

The CSO filter in libMirage in CDemu did not validate the part size, triggering a heap-based buffer overflow that could lead to root access by a local user (CVE-2019-15540).

NULL pointer dereference in the NRG parser (CVE-2019-15757).

References
Credits

Affected packages

Mageia:7 / libmirage

Package

Name
libmirage
Purl
pkg:rpm/mageia/libmirage?arch=source&distro=mageia-7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.2.3-1.mga7

Ecosystem specific

{
    "section": "core"
}