SUSE-SU-2018:0100-1
Dashboard / Vulnerabilities / SUSE-SU-2018:0100-1
SUSE-SU-2018:0100-1
Summary: Security update for openslp
Details: This update for openslp fixes two security issues and two bugs. The following vulnerabilities were fixed: - CVE-2016-4912: A remote attacker could have crashed the server with a large number of packages (bsc#980722) - CVE-2016-7567: A remote attacker could cause a memory corruption having unspecified impact (bsc#1001600) The following bugfix changes are included: - bsc#994989: Removed convenience code as changes bytes in the message buffer breaking the verification code - bsc#974655: Removed no longer needed slpd init file
References: https://www.suse.com/support/update/announcement/2018/suse-su-20180100-1/, https://bugzilla.suse.com/1001600, https://bugzilla.suse.com/974655, https://bugzilla.suse.com/980722, https://bugzilla.suse.com/994989, https://www.suse.com/security/cve/CVE-2016-4912, https://www.suse.com/security/cve/CVE-2016-7567
Affected packages
Package
Name: openslp
Purl: pkg:rpm/suse/openslp&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP2
Affected ranges
Type: ECOSYSTEM
Events:
