Security Fix(es):
In the ffghtb function in NASA CFITSIO 3.42, specially crafted images parsed via the library can cause a stack-based buffer overflow overwriting arbitrary data. An attacker can deliver an FIT image to trigger this vulnerability and potentially gain code execution.(CVE-2018-3849)
In the ffghbn function in NASA CFITSIO 3.42, specially crafted images parsed via the library can cause a stack-based buffer overflow overwriting arbitrary data. An attacker can deliver an FIT image to trigger this vulnerability and potentially gain code execution.(CVE-2018-3848)
{
"severity": "High"
}{
"aarch64": [
"cfitsio-debugsource-3.490-1.oe2203.aarch64.rpm",
"cfitsio-devel-3.490-1.oe2203.aarch64.rpm",
"fpack-3.490-1.oe2203.aarch64.rpm",
"cfitsio-3.490-1.oe2203.aarch64.rpm",
"cfitsio-debuginfo-3.490-1.oe2203.aarch64.rpm"
],
"src": [
"cfitsio-3.490-1.oe2203.src.rpm"
],
"x86_64": [
"cfitsio-devel-3.490-1.oe2203.x86_64.rpm",
"cfitsio-debuginfo-3.490-1.oe2203.x86_64.rpm",
"cfitsio-3.490-1.oe2203.x86_64.rpm",
"cfitsio-debugsource-3.490-1.oe2203.x86_64.rpm",
"fpack-3.490-1.oe2203.x86_64.rpm"
],
"noarch": [
"cfitsio-help-3.490-1.oe2203.noarch.rpm"
]
}