|Summary:||CVE-2012-2090 SimGear, FlightGear: Multiple format string flaws|
|Product:||[Other] Security Response||Reporter:||Jan Lieskovsky <jlieskov>|
|Component:||vulnerability||Assignee:||Red Hat Product Security <security-response-team>|
|Status:||CLOSED ERRATA||QA Contact:|
|Fixed In Version:||Doc Type:||Bug Fix|
|Doc Text:||Story Points:||---|
|Last Closed:||2017-05-16 15:07:39 UTC||Type:||---|
|oVirt Team:||---||RHEL 7.3 requirements from Atomic Host:|
|Cloudforms Team:||---||Target Upstream Version:|
|Bug Depends On:||811634, 811636|
Description Jan Lieskovsky 2012-04-11 14:34:26 UTC
Multiple format string flaws were reported:  http://sourceforge.net/mailarchive/message.php?msg_id=28957051 in the way Flight Gear, the flight simulator, and SimGear, a simulation library components performed retrieval of various data chunk values from XML aircraft (FlightGear) or scene graph (SimGear) model data files. A remote attacker could provide a specially-crafted XML model file, which once opened by a local, unsuspecting user in FlightGear / in an application linked against SimGear, would lead to that particular executable crash. CVE Request:  http://www.openwall.com/lists/oss-security/2012/04/10/9 CVE Assignment:  http://www.openwall.com/lists/oss-security/2012/04/10/13 Upstream patch: None as of right now.
Comment 1 Jan Lieskovsky 2012-04-11 15:13:30 UTC
Created FlightGear tracking bugs for this issue Affects: fedora-all [bug 811634]
Comment 2 Jan Lieskovsky 2012-04-11 15:20:23 UTC
Created SimGear tracking bugs for this issue Affects: fedora-all [bug 811636]
Comment 3 Fedora Update System 2012-06-08 23:56:50 UTC
FlightGear-2.4.0-2.fc16, SimGear-2.4.0-4.fc16 has been pushed to the Fedora 16 stable repository. If problems still persist, please make note of it in this bug report.
Comment 4 Fedora Update System 2012-06-08 23:58:18 UTC
FlightGear-2.6.0-2.fc17, SimGear-2.6.0-2.fc17 has been pushed to the Fedora 17 stable repository. If problems still persist, please make note of it in this bug report.
Comment 5 Fedora Update System 2012-06-09 00:01:33 UTC
FlightGear-2.0.0-6.fc15, SimGear-2.0.0-6.fc15 has been pushed to the Fedora 15 stable repository. If problems still persist, please make note of it in this bug report.