Library for manipulating FITS data files.
Security Fix(es):
In the ffghtb function in NASA CFITSIO 3.42, specially crafted images parsed via the library can cause a stack-based buffer overflow overwriting arbitrary data. An attacker can deliver an FIT image to trigger this vulnerability and potentially gain code execution.(CVE-2018-3849)
In the ffghbn function in NASA CFITSIO 3.42, specially crafted images parsed via the library can cause a stack-based buffer overflow overwriting arbitrary data. An attacker can deliver an FIT image to trigger this vulnerability and potentially gain code execution.(CVE-2018-3848)
{ "severity": "High" }
{ "noarch": [ "cfitsio-help-3.490-1.oe1.noarch.rpm" ], "x86_64": [ "fpack-3.490-1.oe1.x86_64.rpm", "cfitsio-debuginfo-3.490-1.oe1.x86_64.rpm", "cfitsio-3.490-1.oe1.x86_64.rpm", "cfitsio-devel-3.490-1.oe1.x86_64.rpm", "cfitsio-debugsource-3.490-1.oe1.x86_64.rpm" ], "src": [ "cfitsio-3.490-1.oe1.src.rpm" ], "aarch64": [ "fpack-3.490-1.oe1.aarch64.rpm", "cfitsio-3.490-1.oe1.aarch64.rpm", "cfitsio-debuginfo-3.490-1.oe1.aarch64.rpm", "cfitsio-debugsource-3.490-1.oe1.aarch64.rpm", "cfitsio-devel-3.490-1.oe1.aarch64.rpm" ] }
{ "noarch": [ "cfitsio-help-3.490-1.oe1.noarch.rpm" ], "x86_64": [ "fpack-3.490-1.oe1.x86_64.rpm", "cfitsio-devel-3.490-1.oe1.x86_64.rpm", "cfitsio-debugsource-3.490-1.oe1.x86_64.rpm", "cfitsio-3.490-1.oe1.x86_64.rpm", "cfitsio-debuginfo-3.490-1.oe1.x86_64.rpm" ], "src": [ "cfitsio-3.490-1.oe1.src.rpm" ], "aarch64": [ "cfitsio-3.490-1.oe1.aarch64.rpm", "cfitsio-debuginfo-3.490-1.oe1.aarch64.rpm", "cfitsio-devel-3.490-1.oe1.aarch64.rpm", "fpack-3.490-1.oe1.aarch64.rpm", "cfitsio-debugsource-3.490-1.oe1.aarch64.rpm" ] }
{ "noarch": [ "cfitsio-help-3.490-1.oe1.noarch.rpm" ], "x86_64": [ "cfitsio-debuginfo-3.490-1.oe1.x86_64.rpm", "cfitsio-devel-3.490-1.oe1.x86_64.rpm", "fpack-3.490-1.oe1.x86_64.rpm", "cfitsio-3.490-1.oe1.x86_64.rpm", "cfitsio-debugsource-3.490-1.oe1.x86_64.rpm" ], "src": [ "cfitsio-3.490-1.oe1.src.rpm" ], "aarch64": [ "fpack-3.490-1.oe1.aarch64.rpm", "cfitsio-3.490-1.oe1.aarch64.rpm", "cfitsio-debuginfo-3.490-1.oe1.aarch64.rpm", "cfitsio-debugsource-3.490-1.oe1.aarch64.rpm", "cfitsio-devel-3.490-1.oe1.aarch64.rpm" ] }