MGASA-2014-0346

Source
https://advisories.mageia.org/MGASA-2014-0346.html
Import Source
https://advisories.mageia.org/MGASA-2014-0346.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2014-0346
Related
Published
2014-08-22T10:58:14Z
Modified
2014-08-22T10:47:50Z
Summary
Updated sdcc packages fix a security vulnerability
Details

Integer overflow, leading to heap-buffer overflow by processing certain file headers via bfd binary. (CVE-2012-3509)

A nonfree package is also now available, which provides components that cannot be included in the core repository.

In addition, this update obsoletes sdcc2.9, which is old and probably has the same security vulnerability.

References
Credits

Affected packages