Back

HIGH

libspiro: stack-based off-by-one buffer overflow in spiro_to_bpath0() in spiro.c

Published Dec 17, 2019

Description

Libspiro through 20190731 has a stack-based buffer overflow in the spiro_to_bpath0() function in spiro.c.

Affected products

Remediation

Red Hat statement

This issue did not affect the versions of libspiro as shipped with Red Hat Enterprise Linux 6, 7, and 8 as they did not include the vulnerable code. The vulnerable function was introduced in a newer version of the package.

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Dec 17, 2019
Updated Aug 5, 2024
Reserved Dec 17, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Dec 17, 2019
ENISA EUVD
Assigner mitre
Published Dec 17, 2019
Updated Aug 5, 2024
Exploited since n/a
EUVD-2019-9443