FS#70042 - [xcftools] [Security] arbitrary code execution (CVE-2019-5087 CVE-2019-5086)
Attached to Project:
Community Packages
Opened by Jonas Witschel (diabonas) - Wednesday, 17 March 2021, 11:51 GMT
Last edited by Alexander F. Rødseth (xyproto) - Friday, 19 March 2021, 11:50 GMT
Opened by Jonas Witschel (diabonas) - Wednesday, 17 March 2021, 11:51 GMT
Last edited by Alexander F. Rødseth (xyproto) - Friday, 19 March 2021, 11:50 GMT
|
Details
Summary
======= The package xcftools is vulnerable to arbitrary code execution via CVE-2019-5087 and CVE-2019-5086. Guidance ======== Upstream has shown no activity whatsoever since the end of 2019, so I suggest applying the patch suggested in the pull request referenced below, i.e. https://github.com/j-jorge/xcftools/commit/59c38e3e45b9112c2bcb4392bccf56e297854f8a.patch References ========== https://security.archlinux.org/AVG-1679 https://talosintelligence.com/vulnerability_reports/TALOS-2019-0879 https://github.com/j-jorge/xcftools/issues/13 https://github.com/j-jorge/xcftools/pull/15 https://talosintelligence.com/vulnerability_reports/TALOS-2019-0878 https://github.com/j-jorge/xcftools/issues/12 |
This task depends upon