SUSE-SU-2019:0571-1
Dashboard / Vulnerabilities / SUSE-SU-2019:0571-1
SUSE-SU-2019:0571-1
Summary: Security update for file
Details: This update for file fixes the following issues: The following security vulnerabilities were addressed: - CVE-2018-10360: Fixed an out-of-bounds read in the function do_core_note in readelf.c, which allowed remote attackers to cause a denial of service (application crash) via a crafted ELF file (bsc#1096974) - CVE-2019-8905: Fixed a stack-based buffer over-read in do_core_note in readelf.c (bsc#1126118) - CVE-2019-8906: Fixed an out-of-bounds read in do_core_note in readelf. c (bsc#1126119) - CVE-2019-8907: Fixed a stack corruption in do_core_note in readelf.c (bsc#1126117)
References: https://www.suse.com/support/update/announcement/2019/suse-su-20190571-1/, https://bugzilla.suse.com/1096974, https://bugzilla.suse.com/1096984, https://bugzilla.suse.com/1126117, https://bugzilla.suse.com/1126118, https://bugzilla.suse.com/1126119, https://www.suse.com/security/cve/CVE-2018-10360, https://www.suse.com/security/cve/CVE-2019-8905, https://www.suse.com/security/cve/CVE-2019-8906, https://www.suse.com/security/cve/CVE-2019-8907
Affected packages
Package
Name: file
Purl: pkg:rpm/suse/file&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015
Affected ranges
Type: ECOSYSTEM
Events:
