ALAS2-2020-1477

Related Vulnerabilities: CVE-2018-18751  

An issue was discovered in GNU gettext 0.19.8. There is a double free in default_add_message in read-catalog.c, related to an invalid free in po_gram_parse in po-gram-gen.y, as demonstrated by lt-msgfmt. (CVE-2018-18751)

ALAS2-2020-1477


Amazon Linux 2 Security Advisory: ALAS-2020-1477
Advisory Release Date: 2020-08-18 19:49 Pacific
Advisory Updated Date: 2020-08-24 23:59 Pacific
Severity: Low
References: CVE-2018-18751 

Issue Overview:

An issue was discovered in GNU gettext 0.19.8. There is a double free in default_add_message in read-catalog.c, related to an invalid free in po_gram_parse in po-gram-gen.y, as demonstrated by lt-msgfmt. (CVE-2018-18751)


Affected Packages:

gettext


Issue Correction:
Run yum update gettext to update your system.

New Packages:
aarch64:
    gettext-0.19.8.1-3.amzn2.aarch64
    gettext-devel-0.19.8.1-3.amzn2.aarch64
    gettext-libs-0.19.8.1-3.amzn2.aarch64
    gettext-debuginfo-0.19.8.1-3.amzn2.aarch64

i686:
    gettext-0.19.8.1-3.amzn2.i686
    gettext-devel-0.19.8.1-3.amzn2.i686
    gettext-libs-0.19.8.1-3.amzn2.i686
    gettext-debuginfo-0.19.8.1-3.amzn2.i686

noarch:
    gettext-common-devel-0.19.8.1-3.amzn2.noarch
    emacs-gettext-0.19.8.1-3.amzn2.noarch

src:
    gettext-0.19.8.1-3.amzn2.src

x86_64:
    gettext-0.19.8.1-3.amzn2.x86_64
    gettext-devel-0.19.8.1-3.amzn2.x86_64
    gettext-libs-0.19.8.1-3.amzn2.x86_64
    gettext-debuginfo-0.19.8.1-3.amzn2.x86_64