Bugzilla – Bug 1189887
VUL-0: CVE-2021-38714: plib: integer overflow could lead to arbitrary code execution
Last modified: 2021-12-01 17:37:01 UTC
In Plib through 1.85, there is an integer overflow vulnerability that could result in arbitrary code execution. The vulnerability is found in ssgLoadTGA() function in src/ssg/ssgLoadTGA.cxx file. Reference: https://sourceforge.net/p/plib/bugs/55/ References: https://bugzilla.redhat.com/show_bug.cgi?id=1997814 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-38714 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-38714 https://sourceforge.net/p/plib/bugs/55/
Affected packages - openSUSE:Backports:SLE-15/plib 1.8.5+svn.2173 - openSUSE:Backports:SLE-15-SP1/plib 1.8.5+svn.2173 - openSUSE:Backports:SLE-15-SP2/plib 1.8.5+svn.2173 - openSUSE:Backports:SLE-15-SP3/plib 1.8.5+svn.2173 - openSUSE:Backports:SLE-15-SP4/plib 1.8.5+svn.2173 - openSUSE:Factory/plib 1.8.5+svn.2173 No upstream patch is available.
I'm afraid there's little to be done here. Upstream doesn't want to fix it, so we'll just wait for a volunteer. Or delete the package if deemed too dangerous.
Updates sent.
This is an autogenerated message for OBS integration: This bug (1189887) was mentioned in https://build.opensuse.org/request/show/915177 15.2+Backports:SLE-15-SP1+Backports:SLE-15-SP2+Backports:SLE-15-SP3 / plib
i filed a droprequest as this package is unmaintained: osc dr openSUSE:Factory plib
openSUSE-RU-2021:1511-1: An update that has one recommended fix can now be installed. Category: recommended (moderate) Bug References: 1189887 CVE References: JIRA References: Sources used: openSUSE Leap 15.2 (src): plib-1.8.5+svn.2173-lp152.5.3.1 openSUSE Backports SLE-15-SP3 (src): plib-1.8.5+svn.2173-bp153.2.3.1 openSUSE Backports SLE-15-SP2 (src): plib-1.8.5+svn.2173-bp152.5.3.1 openSUSE Backports SLE-15-SP1 (src): plib-1.8.5+svn.2173-bp151.4.3.1
openSUSE-RU-2021:1514-1: An update that has one recommended fix can now be installed. Category: recommended (moderate) Bug References: 1189887 CVE References: JIRA References: Sources used: openSUSE Backports SLE-15-SP2 (src): plib-1.8.5+svn.2173-bp152.5.6.1