Buffer overflow in matio - CVE-2019-9026
Published: February 23, 2019 / Updated: August 8, 2020
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
An issue was discovered in libmatio.a in matio (aka MAT File I/O Library) 1.5.13. There is a heap-based buffer overflow in the function InflateVarName() in inflate.c when called from ReadNextCell in mat5.c.
Affected software
Fedora
libASL
matio
openmeeg
How to mitigate CVE-2019-9026
matio - update to 1.5.17-3.el7
openmeeg - update to 2.4-0.4.rc4.el7