An exploitable buffer overflow vulnerability exists in the LoadEncoding functionality of the R programming language version 3.3.0. A specially crafted R script can cause a buffer overflow resulting in a memory corruption. An attacker can send a malicious R script to trigger this vulnerability.
{
"availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro",
"binaries": [
{
"binary_name": "r-base",
"binary_version": "3.0.2-1ubuntu1.1~esm2"
},
{
"binary_name": "r-base-core",
"binary_version": "3.0.2-1ubuntu1.1~esm2"
},
{
"binary_name": "r-base-dev",
"binary_version": "3.0.2-1ubuntu1.1~esm2"
},
{
"binary_name": "r-base-html",
"binary_version": "3.0.2-1ubuntu1.1~esm2"
},
{
"binary_name": "r-doc-html",
"binary_version": "3.0.2-1ubuntu1.1~esm2"
},
{
"binary_name": "r-doc-info",
"binary_version": "3.0.2-1ubuntu1.1~esm2"
},
{
"binary_name": "r-doc-pdf",
"binary_version": "3.0.2-1ubuntu1.1~esm2"
},
{
"binary_name": "r-mathlib",
"binary_version": "3.0.2-1ubuntu1.1~esm2"
},
{
"binary_name": "r-recommended",
"binary_version": "3.0.2-1ubuntu1.1~esm2"
}
]
}
{
"availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
"binaries": [
{
"binary_name": "r-base",
"binary_version": "3.2.3-4ubuntu0.1~esm3"
},
{
"binary_name": "r-base-core",
"binary_version": "3.2.3-4ubuntu0.1~esm3"
},
{
"binary_name": "r-base-dev",
"binary_version": "3.2.3-4ubuntu0.1~esm3"
},
{
"binary_name": "r-base-html",
"binary_version": "3.2.3-4ubuntu0.1~esm3"
},
{
"binary_name": "r-doc-html",
"binary_version": "3.2.3-4ubuntu0.1~esm3"
},
{
"binary_name": "r-doc-info",
"binary_version": "3.2.3-4ubuntu0.1~esm3"
},
{
"binary_name": "r-doc-pdf",
"binary_version": "3.2.3-4ubuntu0.1~esm3"
},
{
"binary_name": "r-mathlib",
"binary_version": "3.2.3-4ubuntu0.1~esm3"
},
{
"binary_name": "r-recommended",
"binary_version": "3.2.3-4ubuntu0.1~esm3"
}
]
}