{"id":"MGASA-2018-0440","summary":"Updated iniparser packages fix security vulnerability","details":"A flaw was found in iniparser version prior to 4.1. A stack buffer\nunderflow in the function iniparser_load() in iniparser.c file which can\nbe triggered by parsing a file that containing a zero-byte. This\nvulnerability may allow an attacker to cause a Denial of Service (DoS).\n","modified":"2026-04-16T04:26:40.647303Z","published":"2018-11-11T21:09:54Z","references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2018-0440.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=23561"},{"type":"REPORT","url":"https://github.com/ndevilla/iniparser/issues/68"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1545824"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/JM5SZJJT2YKW6NSUEDTA7J4RSLYWP37D/"}],"affected":[{"package":{"name":"iniparser","ecosystem":"Mageia:6","purl":"pkg:rpm/mageia/iniparser?arch=source&distro=mageia-6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.1-8.mga6"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2018-0440.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}