Mageia 2022-0066: nas security update
Summary
Stack-based buffer overflow in auphone.c that can be triggered by an environment variable. Also, the x11-util-cf-files package has been patched to allow building nas.
References
- https://bugs.mageia.org/show_bug.cgi?id=30020
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/KQX5YL7OVJTMPDFFPFACDNNE2LEUDC3J/
- https://sourceforge.net/p/nas/bugs/8/
- https://bugzilla.redhat.com/show_bug.cgi?id=1943020
Resolution
MGASA-2022-0066 - Updated nas packages fix security vulnerability
SRPMS
- 8/core/nas-1.9.4-11.1.mga8
- 8/core/x11-util-cf-files-1.0.6-5.1.mga8