Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-36489

Опубликовано: 03 фев. 2023
Источник: debian

Описание

Buffer Overflow vulnerability in Allegro through 5.2.6 allows attackers to cause a denial of service via crafted PCX/TGA/BMP files to allegro_image addon.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
allegro4.4unfixedpackage
allegro4.4ignoredtrixiepackage
allegro4.4ignoredbookwormpackage
allegro4.4no-dsabullseyepackage
allegro4.4no-dsabusterpackage
allegro5fixed2:5.2.8.0-1package
allegro5fixed2:5.2.6.0-3+deb11u1bullseyepackage
allegro5no-dsabusterpackage

Примечания

  • https://github.com/liballeg/allegro5/issues/1251

  • https://github.com/liballeg/allegro5/pull/1253

  • https://github.com/liballeg/allegro5/commit/3f2dbd494241774d33aaf83910fd05b2a590604a (5.2.8.0)

  • https://github.com/liballeg/allegro5/commit/cca179bc16827f358153060cd10ac73d394e758c (5.2.8.0)

  • https://github.com/liballeg/allegro5/commit/a2c93939f6997a96ecac1865dbb4fa3f66b5e1b7 (5.2.8.0)

  • https://github.com/liballeg/allegro5/commit/0294e28e6135292eab4b2916a7d2223b1bb6843e (5.2.8.0)

  • In allegro 4.4, code is in src/[pcx|tga].c instead

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 3 лет назад

Buffer Overflow vulnerability in Allegro through 5.2.6 allows attackers to cause a denial of service via crafted PCX/TGA/BMP files to allegro_image addon.

CVSS3: 6.5
nvd
около 3 лет назад

Buffer Overflow vulnerability in Allegro through 5.2.6 allows attackers to cause a denial of service via crafted PCX/TGA/BMP files to allegro_image addon.

CVSS3: 6.5
github
около 3 лет назад

Buffer Overflow vulnerability in Allegro through 5.2.6 allows attackers to cause a denial of service via crafted PCX/TGA/BMP files to allegro_image addon.