{"id":"MGASA-2014-0533","summary":"Updated unrtf package fixes security vulnerabilities","details":"Updated unrtf package fixes security vulnerabilities:\n\nMichal Zalewski reported an out-of-bounds memory access vulnerability in\nunrtf.  Processing a malformed RTF file could lead to a segfault while\naccessing a pointer that may be under the attacker's control.  This would\nlead to a denial of service (application crash) or, potentially, the\nexecution of arbitrary code (CVE-2014-9274).\n\nHanno Böck also reported a number of other crashes in unrtf (CVE-2014-9275).\n","modified":"2026-04-16T06:26:31.560724111Z","published":"2014-12-19T15:06:35Z","upstream":["CVE-2014-9274","CVE-2014-9275"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2014-0533.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=14783"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1170233"}],"affected":[{"package":{"name":"unrtf","ecosystem":"Mageia:4","purl":"pkg:rpm/mageia/unrtf?arch=source&distro=mageia-4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.21.7-1.mga4"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2014-0533.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}