Mageia alert MGASA-2021-0333 (libcroco)
| From: | Mageia Updates <buildsystem-daemon@mageia.org> | |
| To: | updates-announce@ml.mageia.org | |
| Subject: | [updates-announce] MGASA-2021-0333: Updated libcroco and gettext packages fix security vulnerability | |
| Date: | Sat, 10 Jul 2021 22:01:38 +0200 | |
| Message-ID: | <20210710200138.CF8F5A0EDF@duvel.mageia.org> | |
| Archive-link: | Article |
MGASA-2021-0333 - Updated libcroco and gettext packages fix security vulnerability Publication date: 10 Jul 2021 URL: https://advisories.mageia.org/MGASA-2021-0333.html Type: security Affected Mageia releases: 7 CVE: CVE-2020-12825 Description: libcroco through 0.6.13 has excessive recursion in cr_parser_parse_any_core in cr-parser.c, leading to stack consumption (CVE-2020-12825). References: - https://bugs.mageia.org/show_bug.cgi?id=27108 - https://access.redhat.com/errata/RHSA-2020:4072 - https://gitlab.gnome.org/Archive/libcroco/-/issues/8 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-1... SRPMS: - 7/core/libcroco-0.6.13-1.2.mga7 - 7/core/gettext-0.19.8.1-4.1.mga7
