Описание
Security update for transfig
This update for transfig fixes the following issues:
Update to fig2dev version 3.2.8 Patchlevel 8b (Aug 2021)
- bsc#1190618, CVE-2020-21529: stack buffer overflow in the bezier_spline function in genepic.c.
- bsc#1190615, CVE-2020-21530: segmentation fault in the read_objects function in read.c.
- bsc#1190617, CVE-2020-21531: global buffer overflow in the conv_pattern_index function in gencgm.c.
- bsc#1190616, CVE-2020-21532: global buffer overflow in the setfigfont function in genepic.c.
- bsc#1190612, CVE-2020-21533: stack buffer overflow in the read_textobject function in read.c.
- bsc#1190611, CVE-2020-21534: global buffer overflow in the get_line function in read.c.
- bsc#1190607, CVE-2020-21535: segmentation fault in the gencgm_start function in gencgm.c.
- bsc#1192019, CVE-2021-32280: NULL pointer dereference in compute_closed_spline() in trans_spline.c
Список пакетов
HPE Helion OpenStack 8
SUSE Linux Enterprise Server 12 SP2-BCL
SUSE Linux Enterprise Server 12 SP3-BCL
SUSE Linux Enterprise Server 12 SP3-LTSS
SUSE Linux Enterprise Server 12 SP4-LTSS
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server for SAP Applications 12 SP3
SUSE Linux Enterprise Server for SAP Applications 12 SP4
SUSE Linux Enterprise Server for SAP Applications 12 SP5
SUSE OpenStack Cloud 8
SUSE OpenStack Cloud 9
SUSE OpenStack Cloud Crowbar 8
SUSE OpenStack Cloud Crowbar 9
Ссылки
- Link for SUSE-SU-2021:3585-1
- E-Mail link for SUSE-SU-2021:3585-1
- SUSE Security Ratings
- SUSE Bug 1190607
- SUSE Bug 1190611
- SUSE Bug 1190612
- SUSE Bug 1190615
- SUSE Bug 1190616
- SUSE Bug 1190617
- SUSE Bug 1190618
- SUSE Bug 1192019
- SUSE CVE CVE-2020-21529 page
- SUSE CVE CVE-2020-21530 page
- SUSE CVE CVE-2020-21531 page
- SUSE CVE CVE-2020-21532 page
- SUSE CVE CVE-2020-21533 page
- SUSE CVE CVE-2020-21534 page
- SUSE CVE CVE-2020-21535 page
- SUSE CVE CVE-2021-32280 page
Описание
fig2dev 3.2.7b contains a stack buffer overflow in the bezier_spline function in genepic.c.
Затронутые продукты
Ссылки
- CVE-2020-21529
- SUSE Bug 1190618
Описание
fig2dev 3.2.7b contains a segmentation fault in the read_objects function in read.c.
Затронутые продукты
Ссылки
- CVE-2020-21530
- SUSE Bug 1190615
Описание
fig2dev 3.2.7b contains a global buffer overflow in the conv_pattern_index function in gencgm.c.
Затронутые продукты
Ссылки
- CVE-2020-21531
- SUSE Bug 1190617
Описание
fig2dev 3.2.7b contains a global buffer overflow in the setfigfont function in genepic.c.
Затронутые продукты
Ссылки
- CVE-2020-21532
- SUSE Bug 1190616
Описание
fig2dev 3.2.7b contains a stack buffer overflow in the read_textobject function in read.c.
Затронутые продукты
Ссылки
- CVE-2020-21533
- SUSE Bug 1190612
Описание
fig2dev 3.2.7b contains a global buffer overflow in the get_line function in read.c.
Затронутые продукты
Ссылки
- CVE-2020-21534
- SUSE Bug 1190611
Описание
fig2dev 3.2.7b contains a segmentation fault in the gencgm_start function in gencgm.c.
Затронутые продукты
Ссылки
- CVE-2020-21535
- SUSE Bug 1190607
Описание
An issue was discovered in fig2dev before 3.2.8.. A NULL pointer dereference exists in the function compute_closed_spline() located in trans_spline.c. It allows an attacker to cause Denial of Service. The fixed version of fig2dev is 3.2.8.
Затронутые продукты
Ссылки
- CVE-2021-32280
- SUSE Bug 1192019