GNU FriBidi: Heap-based buffer overflow A heap-based buffer overflow in GNU FriBidi might allow remote attackers to execute arbitrary code. fribidi 2020-03-19 2020-03-19 699338 local, remote 1.0.8 1.0.8

The Free Implementation of the Unicode Bidirectional Algorithm.

A heap-based buffer overflow vulnerability was found in GNU FriBidi.

A remote attacker could possibly cause a memory corruption, execute arbitrary code with the privileges of the process or cause a Denial of Service condition.

There is no known workaround at this time.

All FriBidi users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=dev-libs/fribidi-1.0.8"
CVE-2019-18397 whissi whissi