Summary: | <media-gfx/potrace-1.12: possible heap overflow (CVE-2013-7437) | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Agostino Sarubbo <ago> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | normal | CC: | fonts, graphics+disabled |
Priority: | Normal | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | https://bugzilla.redhat.com/show_bug.cgi?id=955808 | ||
Whiteboard: | B3 [noglsa cve] | ||
Package list: | Runtime testing required: | --- |
Description
Agostino Sarubbo
![]() CVE-2013-7437 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-7437): Multiple integer overflows in potrace 1.11 allow remote attackers to cause a denial of service (crash) via large dimensions in a BMP image, which triggers a buffer overflow. Arches go ahead and stabilize 1.12. amd64 stable Stable for HPPA. Stable for PPC64. x86 stable ppc stable arm stable alpha stable sparc stable ia64 stable @maintainer(s), please clean the vulnerable versions from the tree. @maintainer(s), please cleanup the vulnerable versions: Re-designating as this is a potential DoS. |