DEBIAN-CVE-2021-36489

Source
https://security-tracker.debian.org/tracker/CVE-2021-36489
Import Source
https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2021-36489.json
JSON Data
https://api.test.osv.dev/v1/vulns/DEBIAN-CVE-2021-36489
Upstream
Published
2023-02-03T18:15:10Z
Modified
2025-09-25T23:25:23.225169Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

Buffer Overflow vulnerability in Allegro through 5.2.6 allows attackers to cause a denial of service via crafted PCX/TGA/BMP files to allegro_image addon.

References

Affected packages

Debian:11

allegro4.4

Package

Name
allegro4.4
Purl
pkg:deb/debian/allegro4.4?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2:4.*

2:4.4.3.1-2
2:4.4.3.1-3
2:4.4.3.1-4
2:4.4.3.1-4.1~exp1
2:4.4.3.1-4.1~exp2
2:4.4.3.1-4.1
2:4.4.3.1-5
2:4.4.3.1-6

Ecosystem specific

{
    "urgency": "not yet assigned"
}

allegro5

Package

Name
allegro5
Purl
pkg:deb/debian/allegro5?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2:5.2.6.0-3+deb11u1

Affected versions

2:5.*

2:5.2.6.0-3

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12

allegro4.4

Package

Name
allegro4.4
Purl
pkg:deb/debian/allegro4.4?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2:4.*

2:4.4.3.1-3
2:4.4.3.1-4
2:4.4.3.1-4.1~exp1
2:4.4.3.1-4.1~exp2
2:4.4.3.1-4.1
2:4.4.3.1-5
2:4.4.3.1-6

Ecosystem specific

{
    "urgency": "not yet assigned"
}

allegro5

Package

Name
allegro5
Purl
pkg:deb/debian/allegro5?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2:5.2.8.0-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13

allegro4.4

Package

Name
allegro4.4
Purl
pkg:deb/debian/allegro4.4?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2:4.*

2:4.4.3.1-5
2:4.4.3.1-6

Ecosystem specific

{
    "urgency": "not yet assigned"
}

allegro5

Package

Name
allegro5
Purl
pkg:deb/debian/allegro5?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2:5.2.8.0-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:14

allegro4.4

Package

Name
allegro4.4
Purl
pkg:deb/debian/allegro4.4?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2:4.*

2:4.4.3.1-5
2:4.4.3.1-6

Ecosystem specific

{
    "urgency": "not yet assigned"
}

allegro5

Package

Name
allegro5
Purl
pkg:deb/debian/allegro5?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2:5.2.8.0-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}