------------------------------------------------------------------------- Debian LTS Advisory DLA-4361-1 debian-lts@lists.debian.org https://www.debian.org/lts/security/ Markus Koschany November 03, 2025 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : geographiclib Version : 1.51-1+deb11u1 CVE ID : CVE-2025-60751 Geographiclib is a C++ library to solve geodesic problems. A stack buffer overflow occurs when the GeoConvert tool receives a crafted input. The overflow occurs because the program does not properly validate an internal index, allowing an out-of-bounds write on the stack. An attacker can exploit this vulnerability to hijack the program's control flow by overwriting a return address to point to a libc function and execute arbitrary code. For Debian 11 bullseye, this problem has been fixed in version 1.51-1+deb11u1. We recommend that you upgrade your geographiclib packages. For the detailed security status of geographiclib please refer to its security tracker page at: https://security-tracker.debian.org/tracker/geographiclib Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS
Attachment:
signature.asc
Description: This is a digitally signed message part