ALT-BU-2021-3910-1
Branch sisyphus update bulletin.
Package kf5-kimageformats updated to version 5.82.0-alt1 for branch sisyphus in task 271665.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2021-36083
KDE KImageFormats 5.70.0 through 5.81.0 has a stack-based buffer overflow in XCFImageFormat::loadTileRLE.
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=33742
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=33742
- https://github.com/google/oss-fuzz-vulns/blob/main/vulns/kimageformats/OSV-2021-695.yaml
- https://github.com/google/oss-fuzz-vulns/blob/main/vulns/kimageformats/OSV-2021-695.yaml
- https://invent.kde.org/frameworks/kimageformats/commit/297ed9a2fe339bfe36916b9fce628c3242e5be0f
- https://invent.kde.org/frameworks/kimageformats/commit/297ed9a2fe339bfe36916b9fce628c3242e5be0f
Closed bugs
rebuild with gcc10 exposes buggy code (with garbage in strings)
Closed vulnerabilities
BDU:2021-05232
Уязвимость функции malloc() библиотеки среды выполнения Klibc, связанная с целочисленным переполнением, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании
BDU:2021-05239
Уязвимость команды cpio библиотеки среды выполнения Klibc на 64-битных системах, связанная с целочисленным переполнением, позволяющая нарушителю вызвать отказ в обслуживании
BDU:2021-05247
Уязвимость функции calloc() библиотеки среды выполнения Klibc, связанная с целочисленным переполнением, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании
Modified: 2024-11-21
CVE-2021-31870
An issue was discovered in klibc before 2.0.9. Multiplication in the calloc() function may result in an integer overflow and a subsequent heap buffer overflow.
- [oss-security] 20210430 [ANNOUNCE] klibc 2.0.9
- [oss-security] 20210430 [ANNOUNCE] klibc 2.0.9
- https://git.kernel.org/pub/scm/libs/klibc/klibc.git/commit/?id=292650f04c2b5348b4efbad61fb014ed09b4f3f2
- https://git.kernel.org/pub/scm/libs/klibc/klibc.git/commit/?id=292650f04c2b5348b4efbad61fb014ed09b4f3f2
- https://kernel.org/pub/linux/libs/klibc/2.0/
- https://kernel.org/pub/linux/libs/klibc/2.0/
- [debian-lts-announce] 20210628 [SECURITY] [DLA 2695-1] klibc security update
- [debian-lts-announce] 20210628 [SECURITY] [DLA 2695-1] klibc security update
- https://lists.zytor.com/archives/klibc/2021-April/004593.html
- https://lists.zytor.com/archives/klibc/2021-April/004593.html
Modified: 2024-11-21
CVE-2021-31871
An issue was discovered in klibc before 2.0.9. An integer overflow in the cpio command may result in a NULL pointer dereference on 64-bit systems.
- [oss-security] 20210430 [ANNOUNCE] klibc 2.0.9
- [oss-security] 20210430 [ANNOUNCE] klibc 2.0.9
- https://git.kernel.org/pub/scm/libs/klibc/klibc.git/commit/?id=2e48a12ab1e30d43498c2d53e878a11a1b5102d5
- https://git.kernel.org/pub/scm/libs/klibc/klibc.git/commit/?id=2e48a12ab1e30d43498c2d53e878a11a1b5102d5
- https://kernel.org/pub/linux/libs/klibc/2.0/
- https://kernel.org/pub/linux/libs/klibc/2.0/
- [debian-lts-announce] 20210628 [SECURITY] [DLA 2695-1] klibc security update
- [debian-lts-announce] 20210628 [SECURITY] [DLA 2695-1] klibc security update
- https://lists.zytor.com/archives/klibc/2021-April/004593.html
- https://lists.zytor.com/archives/klibc/2021-April/004593.html
Modified: 2024-11-21
CVE-2021-31873
An issue was discovered in klibc before 2.0.9. Additions in the malloc() function may result in an integer overflow and a subsequent heap buffer overflow.
- [oss-security] 20210430 [ANNOUNCE] klibc 2.0.9
- [oss-security] 20210430 [ANNOUNCE] klibc 2.0.9
- https://git.kernel.org/pub/scm/libs/klibc/klibc.git/commit/?id=a31ae8c508fc8d1bca4f57e9f9f88127572d5202
- https://git.kernel.org/pub/scm/libs/klibc/klibc.git/commit/?id=a31ae8c508fc8d1bca4f57e9f9f88127572d5202
- https://github.com/huolinjue/klibc/commit/a31ae8c508fc8d1bca4f57e9f9f88127572d5202
- https://github.com/huolinjue/klibc/commit/a31ae8c508fc8d1bca4f57e9f9f88127572d5202
- https://kernel.org/pub/linux/libs/klibc/2.0/
- https://kernel.org/pub/linux/libs/klibc/2.0/
- [debian-lts-announce] 20210628 [SECURITY] [DLA 2695-1] klibc security update
- [debian-lts-announce] 20210628 [SECURITY] [DLA 2695-1] klibc security update
- https://lists.zytor.com/archives/klibc/2021-April/004593.html
- https://lists.zytor.com/archives/klibc/2021-April/004593.html