Bug 1197355 - (CVE-2021-32434) VUL-0: CVE-2021-32434: abcm2ps: multiple security vulnerabilities
(CVE-2021-32434)
VUL-0: CVE-2021-32434: abcm2ps: multiple security vulnerabilities
Status: RESOLVED FIXED
Classification: openSUSE
Product: openSUSE Distribution
Classification: openSUSE
Component: Security
Leap 15.4
Other Other
: P3 - Medium : Normal (vote)
: ---
Assigned To: Security Team bot
Security Team bot
https://smash.suse.de/issue/325980/
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2022-03-21 15:51 UTC by Gabriele Sonnu
Modified: 2022-03-31 15:51 UTC (History)
0 users

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Gabriele Sonnu 2022-03-21 15:51:55 UTC
Three new CVEs were found in abcm2ps package version 8.14.11:

CVE-2021-32434

abcm2ps v8.14.11 was discovered to contain an out-of-bounds read in the function calculate_beam at draw.c.

https://github.com/leesavide/abcm2ps/commit/2f56e1179cab6affeb8afa9d6c324008fe40d8e3
https://github.com/leesavide/abcm2ps/issues/83

CVE-2021-32435

Stack-based buffer overflow in the function get_key in parse.c of abcm2ps v8.14.11 allows remote attackers to cause a Denial of Service (DoS) via unspecified vectors.

https://github.com/leesavide/abcm2ps/commit/3169ace6d63f6f517a64e8df0298f44a490c4a15
https://github.com/leesavide/abcm2ps/issues/84

CVE-2021-32436

An out-of-bounds read in the function write_title() in subs.c of abcm2ps v8.14.11 allows remote attackers to cause a Denial of Service (DoS) via unspecified vectors.

https://github.com/leesavide/abcm2ps/commit/2f56e1179cab6affeb8afa9d6c324008fe40d8e3
https://github.com/leesavide/abcm2ps/issues/85

References:
https://bugzilla.redhat.com/show_bug.cgi?id=2063268
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-32434
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-32434
https://github.com/leesavide/abcm2ps/commit/2f56e1179cab6affeb8afa9d6c324008fe40d8e3
https://github.com/leesavide/abcm2ps/issues/83
Comment 1 Gabriele Sonnu 2022-03-21 15:53:41 UTC
Factory is already fixed (v8.14.13), only openSUSE:Backports:SLE-15-SP3/abcm2ps is affected (v8.14.7).
Comment 2 Michael Vetter 2022-03-21 17:08:44 UTC
Added CVE numbers to changelog as well.

SR#963753 to Factory
SR#963754 to Leap 15.3 Update
SR#963755 to Leap 15.4
Comment 3 OBSbugzilla Bot 2022-03-21 17:40:03 UTC
This is an autogenerated message for OBS integration:
This bug (1197355) was mentioned in
https://build.opensuse.org/request/show/963754 Backports:SLE-15-SP3 / abcm2ps
https://build.opensuse.org/request/show/963755 Backports:SLE-15-SP4 / abcm2ps
Comment 4 Michael Vetter 2022-03-22 10:08:07 UTC
SR#963754 accepted
Comment 5 Swamp Workflow Management 2022-03-31 13:18:06 UTC
openSUSE-SU-2022:0100-1: An update that fixes three vulnerabilities is now available.

Category: security (moderate)
Bug References: 1197355
CVE References: CVE-2021-32434,CVE-2021-32435,CVE-2021-32436
JIRA References: 
Sources used:
openSUSE Backports SLE-15-SP3 (src):    abcm2ps-8.14.13-bp153.2.3.1
Comment 6 Marcus Meissner 2022-03-31 15:51:49 UTC
released