ALAS2-2020-1434

Related Vulnerabilities: CVE-2019-18397  

A buffer overflow in the fribidi_get_par_embedding_levels_ex() function in lib/fribidi-bidi.c of GNU FriBidi through 1.0.7 allows an attacker to cause a denial of service or possibly execute arbitrary code by delivering crafted text content to a user, when this content is then rendered by an application that uses FriBidi for text layout calculations. Examples include any GNOME or GTK+ based application that uses Pango for text layout, as this internally uses FriBidi for bidirectional text layout. For example, the attacker can construct a crafted text file to be opened in GEdit, or a crafted IRC message to be viewed in HexChat. (CVE-2019-18397)

ALAS2-2020-1434


Amazon Linux 2 Security Advisory: ALAS-2020-1434
Advisory Release Date: 2020-06-03 18:24 Pacific
Advisory Updated Date: 2020-06-03 19:02 Pacific
Severity: Important
References: CVE-2019-18397 

Issue Overview:

A buffer overflow in the fribidi_get_par_embedding_levels_ex() function in lib/fribidi-bidi.c of GNU FriBidi through 1.0.7 allows an attacker to cause a denial of service or possibly execute arbitrary code by delivering crafted text content to a user, when this content is then rendered by an application that uses FriBidi for text layout calculations. Examples include any GNOME or GTK+ based application that uses Pango for text layout, as this internally uses FriBidi for bidirectional text layout. For example, the attacker can construct a crafted text file to be opened in GEdit, or a crafted IRC message to be viewed in HexChat. (CVE-2019-18397)


Affected Packages:

fribidi


Issue Correction:
Run yum update fribidi to update your system.

New Packages:
aarch64:
    fribidi-1.0.2-1.amzn2.1.aarch64
    fribidi-devel-1.0.2-1.amzn2.1.aarch64
    fribidi-debuginfo-1.0.2-1.amzn2.1.aarch64

i686:
    fribidi-1.0.2-1.amzn2.1.i686
    fribidi-devel-1.0.2-1.amzn2.1.i686
    fribidi-debuginfo-1.0.2-1.amzn2.1.i686

src:
    fribidi-1.0.2-1.amzn2.1.src

x86_64:
    fribidi-1.0.2-1.amzn2.1.x86_64
    fribidi-devel-1.0.2-1.amzn2.1.x86_64
    fribidi-debuginfo-1.0.2-1.amzn2.1.x86_64