ALT-BU-2023-2246-1
Branch c9f2 update bulletin.
Closed vulnerabilities
BDU:2022-06694
Уязвимость функции asn1_encode_simple_der() библиотеки Libtasn1, позволяющая нарушителю раскрыть защищаемую информацию или вызвать отказ в обслуживании
Modified: 2024-11-21
CVE-2021-46848
GNU Libtasn1 before 4.19.0 has an ETYPE_OK off-by-one array size check that affects asn1_encode_simple_der.
- https://bugs.gentoo.org/866237
- https://bugs.gentoo.org/866237
- https://gitlab.com/gnutls/libtasn1/-/commit/44a700d2051a666235748970c2df047ff207aeb5
- https://gitlab.com/gnutls/libtasn1/-/commit/44a700d2051a666235748970c2df047ff207aeb5
- https://gitlab.com/gnutls/libtasn1/-/issues/32
- https://gitlab.com/gnutls/libtasn1/-/issues/32
- [debian-lts-announce] 20230109 [SECURITY] [DLA 3263-1] libtasn1-6 security update
- [debian-lts-announce] 20230109 [SECURITY] [DLA 3263-1] libtasn1-6 security update
- FEDORA-2022-3c933ffaca
- FEDORA-2022-3c933ffaca
- FEDORA-2022-3f9ee1ad91
- FEDORA-2022-3f9ee1ad91
- FEDORA-2022-061f857481
- FEDORA-2022-061f857481
- FEDORA-2022-19056934a7
- FEDORA-2022-19056934a7
- https://security.netapp.com/advisory/ntap-20221118-0006/
- https://security.netapp.com/advisory/ntap-20221118-0006/
Closed vulnerabilities
Modified: 2024-11-21
CVE-2022-30067
GIMP 2.10.30 and 2.99.10 are vulnerable to Buffer Overflow. Through a crafted XCF file, the program will allocate for a huge amount of memory, resulting in insufficient memory or program crash.
Modified: 2024-11-21
CVE-2022-32990
An issue in gimp_layer_invalidate_boundary of GNOME GIMP 2.10.30 allows attackers to trigger an unhandled exception via a crafted XCF file, causing a Denial of Service (DoS).
Closed vulnerabilities
Modified: 2024-11-21
CVE-2017-12921
PFileFlashPixView::GetGlobalInfoProperty in f_fpxvw.cpp in libfpx 1.3.1_p6 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted fpx image.
- [oss-security] 20170817 libfpx: NULL pointer dereference in PFileFlashPixView:etGlobalInfoProperty (f_fpxvw.cpp)
- [oss-security] 20170817 libfpx: NULL pointer dereference in PFileFlashPixView:etGlobalInfoProperty (f_fpxvw.cpp)
- https://blogs.gentoo.org/ago/2017/08/09/libfpx-null-pointer-dereference-in-pfileflashpixviewgetglobalinfoproperty-f_fpxvw-cpp/
- https://blogs.gentoo.org/ago/2017/08/09/libfpx-null-pointer-dereference-in-pfileflashpixviewgetglobalinfoproperty-f_fpxvw-cpp/
Modified: 2024-11-21
CVE-2017-12925
Double free vulnerability in DfFromLB in docfile.cxx in libfpx 1.3.1_p6 allows remote attackers to cause a denial of service via a crafted fpx image.
- [oss-security] 20170817 libfpx: double-free in DfFromLB (docfile.cxx)
- [oss-security] 20170817 libfpx: double-free in DfFromLB (docfile.cxx)
- https://blogs.gentoo.org/ago/2017/08/09/libfpx-double-free-in-dffromlb-docfile-cxx/
- https://blogs.gentoo.org/ago/2017/08/09/libfpx-double-free-in-dffromlb-docfile-cxx/