ALAS2-2023-2043

Related Vulnerabilities: CVE-2021-42700   CVE-2021-42702   CVE-2021-42704  

Inkscape 0.91 is vulnerable to an out-of-bounds read, which may allow an attacker to have access to unauthorized information. (CVE-2021-42700) Inkscape version 0.91 can access an uninitialized pointer, which may allow an attacker to have access to unauthorized information. (CVE-2021-42702) Inkscape version 0.91 is vulnerable to an out-of-bounds write, which may allow an attacker to arbitrary execute code. (CVE-2021-42704)

ALAS2-2023-2043


Amazon Linux 2 Security Advisory: ALAS-2023-2043
Advisory Release Date: 2023-05-11 17:49 Pacific
Advisory Updated Date: 2023-05-16 15:14 Pacific
Severity: Medium

Issue Overview:

Inkscape 0.91 is vulnerable to an out-of-bounds read, which may allow an attacker to have access to unauthorized information. (CVE-2021-42700)

Inkscape version 0.91 can access an uninitialized pointer, which may allow an attacker to have access to unauthorized information. (CVE-2021-42702)

Inkscape version 0.91 is vulnerable to an out-of-bounds write, which may allow an attacker to arbitrary execute code. (CVE-2021-42704)


Affected Packages:

inkscape


Issue Correction:
Run yum update inkscape to update your system.

New Packages:
aarch64:
    inkscape-0.92.2-3.amzn2.0.1.aarch64
    inkscape-view-0.92.2-3.amzn2.0.1.aarch64
    inkscape-docs-0.92.2-3.amzn2.0.1.aarch64
    inkscape-debuginfo-0.92.2-3.amzn2.0.1.aarch64

i686:
    inkscape-0.92.2-3.amzn2.0.1.i686
    inkscape-view-0.92.2-3.amzn2.0.1.i686
    inkscape-docs-0.92.2-3.amzn2.0.1.i686
    inkscape-debuginfo-0.92.2-3.amzn2.0.1.i686

src:
    inkscape-0.92.2-3.amzn2.0.1.src

x86_64:
    inkscape-0.92.2-3.amzn2.0.1.x86_64
    inkscape-view-0.92.2-3.amzn2.0.1.x86_64
    inkscape-docs-0.92.2-3.amzn2.0.1.x86_64
    inkscape-debuginfo-0.92.2-3.amzn2.0.1.x86_64