leptonica through version 1.74.4 is vulnerable to a stack-based buffer overflow in gplot.c:gplotRead() and ptabasic.c:ptaReadStream() when parsing crafted files, leading to a denial of service. Upstream patch: https://github.com/DanBloomberg/leptonica/commit/ee301cb2029db8a6289c5295daa42bba7715e99a Additional References: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=890548
Created leptonica tracking bugs for this issue: Affects: epel-all [bug 1542007] Affects: fedora-all [bug 1542008] Created mingw-leptonica tracking bugs for this issue: Affects: fedora-all [bug 1542009]