Advisories ยป MGASA-2014-0346

Updated sdcc packages fix a security vulnerability

Publication date: 22 Aug 2014
Type: security
Affected Mageia releases : 3 , 4
CVE: CVE-2012-3509

Description

Integer overflow, leading to heap-buffer overflow by processing certain
file headers via bfd binary. (CVE-2012-3509)

A nonfree package is also now available, which provides components that
cannot be included in the core repository.

In addition, this update obsoletes sdcc2.9, which is old and probably has
the same security vulnerability.
                

References

SRPMS

4/nonfree

4/core

3/nonfree

3/core