Hide Forgot
CFITSIO through version 3.42 has a stack-based buffer overflow vulnerability in the ffghtb() function that can potentially allow an attacker to execute code via a crafted FIT image file. External References: https://www.talosintelligence.com/vulnerability_reports/TALOS-2018-0531 https://heasarc.gsfc.nasa.gov/FTP/software/fitsio/c/docs/changes2.txt Additional References: https://github.com/astropy/astropy/pull/7274
Created cfitsio tracking bugs for this issue: Affects: fedora-all [bug 1568189] Affects: epel-all [bug 1568186]
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2018-3849