MPFR: Denial of Service Multiple buffer overflows in MPFR might lead to a Denial of Service. mpfr March 09, 2009 March 09, 2009: 01 260968 remote 2.4.1 2.4.1

MPFR is a library for multiple-precision floating-point computations with exact rounding.

Multiple buffer overflows have been reported in the mpfr_snprintf() and mpfr_vsnprintf() functions.

A remote user could exploit the vulnerability to cause a Denial of Service in an application using MPFR via unknown vectors.

There is no known workaround at this time.

All MPRF users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=dev-libs/mpfr-2.4.1"
CVE-2009-0757 rbu rbu rbu