Stack-based buffer overflow in fribidi - CVE-2019-18397
Published: November 10, 2019 / Updated: March 25, 2020
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error in GNU fribidi when processing a large number of unicode isolate directional characters. A remote attacker can trigger stack-based buffer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Gentoo Linux
SUSE MicroOS
Red Hat Enterprise Linux for Power
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for IBM z Systems
SUSE Linux Enterprise Module for Desktop Applications
SUSE Linux Enterprise Module for Basesystem
Fedora
fribidi (Debian package)
fribidi (Alpine package)
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
fribidi-debuginfo
fribidi-debugsource
libfribidi0
libfribidi0-debuginfo
libfribidi0-32bit
libfribidi0-32bit-debuginfo
fribidi
fribidi-devel
Data Computing Appliance (DCA)
How to mitigate CVE-2019-18397
fribidi (Debian package) - update to 1.0.5-3.1+deb10u1
fribidi (Alpine package) - update to 1.0.2-r1
fribidi-debuginfo - update to 1.0.5-3.3.1
fribidi-debugsource - update to 1.0.5-3.3.1
libfribidi0 - update to 1.0.5-3.3.1
libfribidi0-debuginfo - update to 1.0.5-3.3.1
libfribidi0-32bit - update to 1.0.5-3.3.1
libfribidi0-32bit-debuginfo - update to 1.0.5-3.3.1
fribidi - update to 1.0.5-3.3.1
fribidi-devel - update to 1.0.5-3.3.1
fribidi - addressed in versions 1.0.5-5.fc30, 1.0.5-5.fc31
Data Computing Appliance (DCA) - update to 4.3.0.0
External References
Related Security Bulletins
- Buffer overflow in GNU fribidi
- Debian update for fribidi
- Red Hat update for fribidi
- Red Hat update for fribidi
- Red Hat update for fribidi
- Gentoo update for GNU FriBidi
- Stack-based buffer overflow in fribidi (Alpine package)
- SUSE update for fribidi
- Multiple vulnerabilities in Dell EMC Data Computing Appliance (DCA)
- Fedora 30 update for fribidi
- Fedora 31 update for fribidi