Debian Security Advisory

DLA-2705-1 scilab -- LTS security update

Date Reported:
08 Jul 2021
Affected Packages:
scilab
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2021-30485, CVE-2021-31229, CVE-2021-31347, CVE-2021-31348, CVE-2021-31598.
More information:

Multiple issues have been discovered in scilab, particularly in ezXML embedded library:

  • CVE-2021-30485

    Descriptionincorrect memory handling, leading to a NULL pointer dereference in ezxml_internal_dtd()

  • CVE-2021-31229

    Out-of-bounds write in ezxml_internal_dtd() leading to out-of-bounds write of a one byte constant

  • CVE-2021-31347, CVE-2021-31348

    incorrect memory handling in ezxml_parse_str() leading to out-of-bounds read

  • CVE-2021-31598

    Out-of-bounds write in ezxml_decode() leading to heap corruption

For Debian 9 stretch, these problems have been fixed in version 5.5.2-4+deb9u1.

We recommend that you upgrade your scilab packages.

For the detailed security status of scilab please refer to its security tracker page at: https://security-tracker.debian.org/tracker/scilab

Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS