Division by zero in libcaca - CVE-2022-0856

 

Division by zero in libcaca - CVE-2022-0856

Published: October 3, 2023


Vulnerability identifier: #VU81450
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-0856
CWE-ID: CWE-369
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a divide by zero error in img2txt. A remote attacker can pass specially crafted input to the application and perform a denial of service attack.


Affected software

libcaca
SUSE Manager Server
SUSE Manager Proxy
Fedora
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Server
Ubuntu
Slackware Linux
SUSE Linux Enterprise Realtime Extension
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise High Performance Computing
openSUSE Leap
libcaca (Ubuntu package)
libcaca0-debuginfo
libcaca0
libcaca0-plugins-debuginfo
libcaca0-plugins
libcaca-devel
libcaca-debugsource
libcaca0-32bit-debuginfo
python3-caca
libcaca0-plugins-32bit-debuginfo
libcaca0-plugins-32bit
libcaca0-32bit
caca-utils
caca-utils-debuginfo
libcaca-ruby
libcaca-ruby-debuginfo
libcaca

How to mitigate CVE-2022-0856

Install updates from vendor's website.

libcaca - update to 0.99
libcaca (Ubuntu package) - addressed in versions 0.99 beta18-1ubuntu5.1+esm3, 0.99 beta19-2.1ubuntu1.20.04.2+esm1, 0.99 beta19-2.2ubuntu4.1, 0.99 beta19-2ubuntu0.16.04.2+esm2, 0.99 beta19-2ubuntu0.18.04.3+esm1, 0.99 beta20-4ubuntu0.1, 0.99 beta20-5ubuntu0.25.04.1, 0.99 beta20-5ubuntu0.25.10.1
libcaca0-debuginfo - addressed in versions 0.99 beta18-14.9.1, 0.99 beta19.git20171003-150200.11.6.1
libcaca0 - addressed in versions 0.99 beta18-14.9.1, 0.99 beta19.git20171003-150200.11.6.1
libcaca0-plugins-debuginfo - addressed in versions 0.99 beta18-14.9.1, 0.99 beta19.git20171003-150200.11.6.1
libcaca0-plugins - addressed in versions 0.99 beta18-14.9.1, 0.99 beta19.git20171003-150200.11.6.1
libcaca-devel - addressed in versions 0.99 beta18-14.9.1, 0.99 beta19.git20171003-150200.11.6.1
libcaca-debugsource - addressed in versions 0.99 beta18-14.9.1, 0.99 beta19.git20171003-150200.11.6.1
libcaca0-32bit-debuginfo - update to 0.99 beta19.git20171003-150200.11.6.1
python3-caca - update to 0.99 beta19.git20171003-150200.11.6.1
libcaca0-plugins-32bit-debuginfo - update to 0.99 beta19.git20171003-150200.11.6.1
libcaca0-plugins-32bit - update to 0.99 beta19.git20171003-150200.11.6.1
libcaca0-32bit - update to 0.99 beta19.git20171003-150200.11.6.1
caca-utils - update to 0.99 beta19.git20171003-150200.11.6.1
caca-utils-debuginfo - update to 0.99 beta19.git20171003-150200.11.6.1
libcaca-ruby - update to 0.99 beta19.git20171003-150200.11.6.1
libcaca-ruby-debuginfo - update to 0.99 beta19.git20171003-150200.11.6.1
libcaca - update to 0.99 beta20
libcaca - addressed in versions 0.99-0.69.beta20.el9, 0.99-0.69.beta20.fc37, 0.99-0.69.beta20.fc38, 0.99-0.69.beta20.fc39, 0.99-0.69.beta20.fc40

External References

Related Security Bulletins