Note:
This project will be discontinued after December 13, 2021. [more]
2019-10-13
Mat_VarReadNextInfo4 in mat4.c in MATIO 1.5.17 omits a certain '\0' character, leading to a heap-based buffer over-read in strdup_vprintf when uninitialized memory is accessed.
Products | Debian_linux, Matio |
Type | Out-of-bounds Read (CWE-125) Use of Uninitialized Resource (CWE-908) |
First patch | - None (likely due to unavailable code) |
Patches | https://github.com/tbeu/matio/commit/651a8e28099edb5fbb9e4e1d4d3238848f446c9a |
Links |
• https://lists.debian.org/debian-lts-announce/2020/06/msg00037.html
• https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=16856 |