Multiple format string flaws were reported: [1] http://sourceforge.net/mailarchive/message.php?msg_id=28957051 in the way Flight Gear, the flight simulator, and SimGear, a simulation library components performed retrieval of various data chunk values from XML aircraft (FlightGear) or scene graph (SimGear) model data files. A remote attacker could provide a specially-crafted XML model file, which once opened by a local, unsuspecting user in FlightGear / in an application linked against SimGear, would lead to that particular executable crash. CVE Request: [2] http://www.openwall.com/lists/oss-security/2012/04/10/9 CVE Assignment: [3] http://www.openwall.com/lists/oss-security/2012/04/10/13 Upstream patch: None as of right now.
Created FlightGear tracking bugs for this issue Affects: fedora-all [bug 811634]
Created SimGear tracking bugs for this issue Affects: fedora-all [bug 811636]
FlightGear-2.4.0-2.fc16, SimGear-2.4.0-4.fc16 has been pushed to the Fedora 16 stable repository. If problems still persist, please make note of it in this bug report.
FlightGear-2.6.0-2.fc17, SimGear-2.6.0-2.fc17 has been pushed to the Fedora 17 stable repository. If problems still persist, please make note of it in this bug report.
FlightGear-2.0.0-6.fc15, SimGear-2.0.0-6.fc15 has been pushed to the Fedora 15 stable repository. If problems still persist, please make note of it in this bug report.