Bugzilla – Bug 1155411
VUL-1: CVE-2019-18604: texlive: improper use of sprintf
Last modified: 2022-03-24 09:15:24 UTC
CVE-2019-18604 In axohelp.c before 1.3 in axohelp in axodraw2 before 2.1.1b, as distributed in TeXLive and other collections, sprintf is mishandled. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-18604 http://people.canonical.com/~ubuntu-security/cve/2019/CVE-2019-18604.html http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-18604 https://github.com/TeX-Live/texlive-source/commit/9216833a3888a4105a18e8c349f65b045ddb1079#diff-987e40c0e27ee43f6a2414ada73a191a
Only Factory is affected. Our internal codestreams as well as Leap versions of OpenSUSE are not affected since they ship an older version.
FIXED with SR#744485
This is an autogenerated message for OBS integration: This bug (1155411) was mentioned in https://build.opensuse.org/request/show/744485 Factory / texlive