Mingw-w64 through 5.0.3 contains an Improper Null Termination vulnerability in mingw-w64-crt/stdio/[v]snprintf.c that can result in memory corruption in subsequent string functions. In certain circumstances, this could allow for exploit by a remote attacker. Upstream Bug: https://sourceforge.net/p/mingw-w64/bugs/709/
Created mingw-w64-tools tracking bugs for this issue: Affects: epel-all [bug 1548933] Affects: fedora-all [bug 1548934]
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.