[ GLSA 202208-04 ] libmcpp: Denial of service

[email protected]
Newsgroups gmane.linux.gentoo.announce
Message-ID <165962122959.8.10151388684109925946@e7cbb8eca0f2>
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory                           GLSA 202208-04
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
                                           https://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

 Severity: Low
    Title: libmcpp: Denial of service
     Date: August 04, 2022
     Bugs: #718808
       ID: 202208-04

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Synopsis
========

Multiple vulnerabilities in libmcpp could result in a denial of service
condition.

Background
==========

libmcpp is a portable C/C++ preprocessor.

Affected packages
=================

    -------------------------------------------------------------------
     Package              /     Vulnerable     /            Unaffected
    -------------------------------------------------------------------
  1  dev-cpp/libmcpp            < 2.7.2_p5                >= 2.7.2_p5 

Description
===========

A buffer overflow and an out-of-bounds read vulnerability have been
discovered in libmcpp, which could be exploited for denial of service.

Impact
======

An attacker that can provide crafted input to libmcpp could achieve denial of service.

Workaround
==========

There is no known workaround at this time.

Resolution
==========

All libmcpp users should upgrade to the latest version:

  # emerge --sync
  # emerge --ask --oneshot --verbose ">=dev-cpp/libmcpp-2.7.2_p5"

References
==========

[ 1 ] CVE-2019-14274
      https://nvd.nist.gov/vuln/detail/CVE-2019-14274

Availability
============

This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:

 https://security.gentoo.org/glsa/202208-04

Concerns?
=========

Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users' machines is of utmost
importance to us. Any security concerns should be addressed to
[email protected] or alternatively, you may file a bug at
https://bugs.gentoo.org.

License
=======

Copyright 2022 Gentoo Foundation, Inc; referenced text
belongs to its owner(s).

The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license.

https://creativecommons.org/licenses/by-sa/2.5
signature.asc (application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEpqTA6ABLMxh/aChGFMQkOaVy+9kFAmLrz20ACgkQFMQkOaVy
+9nRIQ//fS3e3G2ewE8tGJ2mBx8NXQajojrCkTzTLL5M+7XvkfFQu+r8Z5oYwDq0
kJ6ICR9I/O4jw4cNsTw6atGaKgMLpohX0QjmQEafvRFE7qba0Dk+LrT8BCgbjF2N
n3Bg15wcmI640FS4wh/SFgxzoFVtsV7sSz2ZJxevNf8pUaqslQPkjtFTZrPAM96M
+4z9DJaeDyN38Zi0cF7I6idcUGU09YIiKZSlHYBUkDy/7WLACguP84ka8W0pENmD
ezSk8P5lY+XYHLotsFnCC5X+5mZYCDVlz7DcLHH4R3gsEXNeWohvBjj588s+6M6O
AEZxm+7BFmL/SoN91Qkvn+PH1Qd2YvzMKZLJqzjH+KWcQ+H7rucWHLVryl4j7IzB
t2Q4VvsFuykdR80TnNFmp7sFWrLvmO/5f951egKtNyK/XqoaUYK8Cr45+B/q4iq3
uv7WP0yrQLZX4NwF026qPOzRWdSpWhH1ZJR3ZigpBnCxYLPekp7CBw4jZ+wBc2/c
uM6Jb5J+C1btlHaQTndDsG1dPE7Ja909w8GA2mtRy9dMI7VM+NQmCQabIiGRxeEO
U0DaXRN2wb+bCRBzubVFcBTZXLrhCOZCTL4DKFVfpdJNKTaNbx1lhyMNR+KZ5IIl
wkZDFw0B77d36RDnBlDuFEzpzL/2IFXShkugc8YfrnAamhhfi2U=
=Zobj
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.