Fedora Account System
Red Hat Associate
Red Hat Customer
A flaw was found in svxlink's LocationInfo/APRS functionality. In AprsTcpClient.cpp, updateQsoStatus() formats a remote EchoLink station's callsign and info into a fixed 80-byte stack buffer using sprintf. A long callsign or info string overflows the buffer, potentially enabling code execution. The overflow has existed since 2010. Fixed in version 26.05.1.