Advisories Blog | G5 Cyber Security

Gentoo Linux Security Advisory 200909-12

Gentoo Linux Security Advisory GLSA 200909-12 – Multiple insecure calls to the sscanf() function in HTMLDOC might result in the execution of arbitrary code. ANTHRAX666 reported an insecure call to the sscanf() function in the set_page_size() function in htmldoc/util.cxx. Nico Golde of the Debian Security Team found two more insecure calls in the write_type1() function in htmldoc/ps-pdf.cxx and the htmlLoadFontWidths() function in htmldoc/htmllib.cxx. Versions less than 1.8.27-r1 are affected.

 

You can download this advisory from the following link: https://packetstormsecurity.com/files/download/81274/glsa-200909-12.txt

Source: https://packetstormsecurity.com/files/81274/Gentoo-Linux-Security-Advisory-200909-12.html

Exit mobile version