SUSE-SU-2018:2979-1
Dashboard / Vulnerabilities / SUSE-SU-2018:2979-1
SUSE-SU-2018:2979-1
Summary: Security update for mgetty
Details: This update for mgetty fixes the following security issues: - CVE-2018-16741: The function do_activate() did not properly sanitize shell metacharacters to prevent command injection (bsc#1108752) - CVE-2018-16745: The mail_to parameter was not sanitized, leading to a buffer overflow if long untrusted input reached it (bsc#1108756) - CVE-2018-16744: The mail_to parameter was not sanitized, leading to command injection if untrusted input reached reach it (bsc#1108757) - CVE-2018-16742: Prevent stack-based buffer overflow that could have been triggered via a command-line parameter (bsc#1108762) - CVE-2018-16743: The command-line parameter username wsa passed unsanitized to strcpy(), which could have caused a stack-based buffer overflow (bsc#1108761)
References: https://www.suse.com/support/update/announcement/2018/suse-su-20182979-1/, https://bugzilla.suse.com/1108752, https://bugzilla.suse.com/1108756, https://bugzilla.suse.com/1108757, https://bugzilla.suse.com/1108761, https://bugzilla.suse.com/1108762, https://www.suse.com/security/cve/CVE-2018-16741, https://www.suse.com/security/cve/CVE-2018-16742, https://www.suse.com/security/cve/CVE-2018-16743, https://www.suse.com/security/cve/CVE-2018-16744, https://www.suse.com/security/cve/CVE-2018-16745
Affected packages
Package
Name: mgetty
Purl: pkg:rpm/suse/mgetty&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP3
Affected ranges
Type: ECOSYSTEM
Events:
