Bug ID 1189887
Summary VUL-0: CVE-2021-38714: plib: integer overflow could lead to arbitrary code execution
Classification openSUSE
Product openSUSE Distribution
Version Leap 15.2
Hardware Other
URL https://smash.suse.de/issue/307938/
OS Other
Status NEW
Severity Normal
Priority P5 - None
Component Security
Assignee aloisio@gmx.com
Reporter gabriele.sonnu@suse.com
QA Contact security-team@suse.de
Found By Security Response Team
Blocker ---

In Plib through 1.85, there is an integer overflow vulnerability that could
result in arbitrary code execution. The vulnerability is found in ssgLoadTGA()
function in src/ssg/ssgLoadTGA.cxx file.

Reference:

https://sourceforge.net/p/plib/bugs/55/

References:
https://bugzilla.redhat.com/show_bug.cgi?id=1997814
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-38714
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-38714
https://sourceforge.net/p/plib/bugs/55/


You are receiving this mail because: