First published: Wed Apr 11 2012(Updated: )
Multiple format string flaws were reported: [1] <a href="http://sourceforge.net/mailarchive/message.php?msg_id=28957051">http://sourceforge.net/mailarchive/message.php?msg_id=28957051</a> in the way Flight Gear, the flight simulator, and SimGear, a simulation library components performed retrieval of various data chunk values from XML aircraft (FlightGear) or scene graph (SimGear) model data files. A remote attacker could provide a specially-crafted XML model file, which once opened by a local, unsuspecting user in FlightGear / in an application linked against SimGear, would lead to that particular executable crash. CVE Request: [2] <a href="http://www.openwall.com/lists/oss-security/2012/04/10/9">http://www.openwall.com/lists/oss-security/2012/04/10/9</a> CVE Assignment: [3] <a href="http://www.openwall.com/lists/oss-security/2012/04/10/13">http://www.openwall.com/lists/oss-security/2012/04/10/13</a> Upstream patch: None as of right now.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Flightgear Flightgear | <=2.6.0 | |
Flightgear Flightgear | =1.9.1 | |
Flightgear Flightgear | =2.0.0 | |
Simgear Simgear | <=2.6.0 | |
Simgear Simgear | =1.9.1 | |
Simgear Simgear | =2.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.