Re: [oss-security] CVE-2024-42415: Integer Overflow in GNOME libgsf

2024-10-04 Thread Alan Coopersmith
On 10/4/24 13:59, Alan Coopersmith wrote: The upstream bug report is at https://gitlab.gnome.org/GNOME/libgsf/-/issues/34 and states the bug is "Fixed in 1.14.53" and https://gitlab.gnome.org/GNOME/libgsf/-/ commit/06d0cb92a4c02e7126ef2ff6f5e29fd74b4be9e0 says it fixes that issue. Oops, I sho

[oss-security] CVE-2024-42415: Integer Overflow in GNOME libgsf

2024-10-04 Thread Alan Coopersmith
https://talosintelligence.com/vulnerability_reports/TALOS-2024-2069 reports: GNOME Project G Structured File Library (libgsf) Compound Document Binary File Sector Allocation Table integer overflow vulnerability October 3, 2024 CVE Number CVE-2024-42415 SUMMARY An integer overflow vulnerabil