CVE-2022-1211

NameCVE-2022-1211
DescriptionA vulnerability classified as critical has been found in tildearrow Furnace dev73. This affects the FUR to VGM converter in console mode which causes stack-based overflows and crashes. It is possible to initiate the attack remotely but it requires user-interaction. A POC has been disclosed to the public and may be used.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
furnace (PTS)sid, trixie0.6.8.1+git20250403+ds-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
furnacesource(unstable)(not affected)

Notes

- furnace <not-affected> (Fixed before initial upload)
https://github.com/tildearrow/furnace/issues/325

Search for package or bug name: Reporting problems