Debian Security Advisory
DLA-2553-1 xcftools -- LTS security update
- Date Reported:
- 10 Feb 2021
- Affected Packages:
- xcftools
- Vulnerable:
- Yes
- Security database references:
- In the Debian bugtracking system: Bug 945317.
In Mitre's CVE dictionary: CVE-2019-5086, CVE-2019-5087. - More information:
-
Claudio Bozzato of Cisco Talos discovered an exploitable integer overflow vulnerability in the flattenIncrementally function in the xcf2png and xcf2pnm binaries of xcftools. An integer overflow can occur while walking through tiles that could be exploited to corrupt memory and execute arbitrary code. In order to trigger this vulnerability, a victim would need to open a specially crafted XCF file.
For Debian 9 stretch, these problems have been fixed in version 1.0.7-6+deb9u1.
We recommend that you upgrade your xcftools packages.
For the detailed security status of xcftools please refer to its security tracker page at: https://security-tracker.debian.org/tracker/xcftools
Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS