Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.bugs.dist > #1069151

Bug#993372: atomicparsley: CVE-2021-37231 - stack-buffer overflow in APar_readX in src/extract.cpp

From Neil Williams <codehelp@debian.org>
Newsgroups linux.debian.bugs.dist
Subject Bug#993372: atomicparsley: CVE-2021-37231 - stack-buffer overflow in APar_readX in src/extract.cpp
Date 2021-08-31 16:10 +0200
Message-ID <CScCB-4N1-3@gated-at.bofh.it> (permalink)
Organization linux.* mail to news gateway

Show all headers | View raw


[Multipart message — attachments visible in raw view] - view raw

Package: atomicparsley
Version: 0.9.6-2
Severity: important
Tags: patch security

https://github.com/wez/atomicparsley/issues/30

See also #993366

AtomicParsley, at the version in buster, bullseye, bookworm and sid causes a stack
overflow when tested with the data file from the upstream bug report for CVE-2021-37231

The upstream change can be backported to the version in Debian and the supplied data file
no longer produces the crash with the attached patch.

-- System Information:
Debian Release: 10.10
  APT prefers oldstable-updates
  APT policy: (500, 'oldstable-updates'), (500, 'oldstable')
Architecture: amd64 (x86_64)

Kernel: Linux 4.19.0-17-amd64 (SMP w/4 CPU cores)
Locale: LANG=en_GB.UTF-8, LC_CTYPE=en_GB.UTF-8 (charmap=UTF-8), LANGUAGE=en_GB:en (charmap=UTF-8)
Shell: /bin/sh linked to /usr/bin/dash
Init: systemd (via /run/systemd/system)
LSM: AppArmor: enabled

Versions of packages atomicparsley depends on:
ii  libc6       2.28-10
ii  libgcc1     1:8.3.0-6
ii  libstdc++6  8.3.0-6
ii  zlib1g      1:1.2.11.dfsg-1

atomicparsley recommends no packages.

atomicparsley suggests no packages.

-- no debconf information

Back to linux.debian.bugs.dist | Previous | Next | Find similar | Unroll thread


Thread

Bug#993372: atomicparsley: CVE-2021-37231 - stack-buffer overflow in APar_readX in src/extract.cpp Neil Williams <codehelp@debian.org> - 2021-08-31 16:10 +0200

csiph-web