{"id":"MGASA-2017-0318","summary":"Updated libgxps packages fix security vulnerability","details":"There is a NULL pointer dereference in the caseless_hash function in\ngxps-archive.c in libgxps 0.2.5. A crafted input will lead to a denial\nof service attack (CVE-2017-11590).\n","modified":"2026-04-16T06:22:47.007042387Z","published":"2017-08-28T22:48:03Z","upstream":["CVE-2017-11590"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2017-0318.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=21526"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/4UCPAG32F7QVCTWKIO5S7U5CKIZQEYJY/"}],"affected":[{"package":{"name":"libgxps","ecosystem":"Mageia:5","purl":"pkg:rpm/mageia/libgxps?arch=source&distro=mageia-5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.2.5-1.1.mga5"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2017-0318.json"}},{"package":{"name":"libgxps","ecosystem":"Mageia:6","purl":"pkg:rpm/mageia/libgxps?arch=source&distro=mageia-6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.2.5-1.1.mga6"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2017-0318.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}