Bugzilla – Bug 1122352
VUL-1: CVE-2019-6458: gnu-recutils: There is a memory leak in rec_buf_new in rec-buf.c when called from rec_parse_rset in rec-parser.c in librec.a.
Last modified: 2019-02-28 18:54:10 UTC
CVE-2019-6458 An issue was discovered in GNU Recutils 1.8. There is a memory leak in rec_buf_new in rec-buf.c when called from rec_parse_rset in rec-parser.c in librec.a. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-6458 http://www.cvedetails.com/cve/CVE-2019-6458/
For more information refer at [1] at number 3 at the third direct leak [1] https://github.com/TeamSeri0us/pocs/tree/master/recutils
We're still at 1.7. Unsure if this concerns us, but upstream says they're working on it.
Upstream unresponsive, package deleted.