------------------------------------------------------------------------- Debian LTS Advisory DLA-2553-1 debian-lts@lists.debian.org https://www.debian.org/lts/security/ Markus Koschany February 09, 2021 https://wiki.debian.org/LTS -------------------------------------------------------------------------
Package : xcftools Version : 1.0.7-6+deb9u1 CVE ID : CVE-2019-5086 CVE-2019-5087 Debian Bug : 945317 Claudio Bozzato of Cisco Talos discovered an exploitable integer overflow vulnerability in the flattenIncrementally function in the xcf2png and xcf2pnm binaries of xcftools. An integer overflow can occur while walking through tiles that could be exploited to corrupt memory and execute arbitrary code. In order to trigger this vulnerability, a victim would need to open a specially crafted XCF file. For Debian 9 stretch, these problems have been fixed in version 1.0.7-6+deb9u1. We recommend that you upgrade your xcftools packages. For the detailed security status of xcftools please refer to its security tracker page at: https://security-tracker.debian.org/tracker/xcftools Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS
signature.asc
Description: This is a digitally signed message part