SUSE-SU-2022:1277-1
Dashboard / Vulnerabilities / SUSE-SU-2022:1277-1
SUSE-SU-2022:1277-1
Summary: Security update for dcraw
Details: This update for dcraw fixes the following issues: - CVE-2017-13735: Fixed a denial of service issue due to a floating point exception (bsc#1056170). - CVE-2017-14608: Fixed an invalid memory access that could lead to information disclosure or denial of service (bsc#1063798). - CVE-2018-19655: Fixed a buffer overflow that could lead to an application crash (bsc#1117896). - CVE-2018-5801: Fixed an invalid memory access that could lead to denial of service (bsc#1084690). - CVE-2018-5805: Fixed a buffer overflow that could lead to an application crash (bsc#1097973). - CVE-2018-5806: Fixed an invalid memory access that could lead to denial of service (bsc#1097974). - CVE-2018-19565: Fixed an invalid memory access that could lead to information disclosure or denial of service (bsc#1117622). - CVE-2018-19566: Fixed an invalid memory access that could lead to information disclosure or denial of service (bsc#1117517). - CVE-2018-19567: Fixed a denial of service issue due to a floating point exception (bsc#1117512). - CVE-2018-19568: Fixed a denial of service issue due to a floating point exception (bsc#1117436). - CVE-2021-3624: Fixed a buffer overflow that could lead to code execution or denial of service (bsc#1189642). Non-security fixes: - Updated to version 9.28.0.
References: https://www.suse.com/support/update/announcement/2022/suse-su-20221277-1/, https://bugzilla.suse.com/1056170, https://bugzilla.suse.com/1063798, https://bugzilla.suse.com/1084690, https://bugzilla.suse.com/1097973, https://bugzilla.suse.com/1097974, https://bugzilla.suse.com/1117436, https://bugzilla.suse.com/1117512, https://bugzilla.suse.com/1117517, https://bugzilla.suse.com/1117622, https://bugzilla.suse.com/1117896, https://bugzilla.suse.com/1189642, https://www.suse.com/security/cve/CVE-2017-13735, https://www.suse.com/security/cve/CVE-2017-14608, https://www.suse.com/security/cve/CVE-2018-19565, https://www.suse.com/security/cve/CVE-2018-19566, https://www.suse.com/security/cve/CVE-2018-19567, https://www.suse.com/security/cve/CVE-2018-19568, https://www.suse.com/security/cve/CVE-2018-19655, https://www.suse.com/security/cve/CVE-2018-5801, https://www.suse.com/security/cve/CVE-2018-5805, https://www.suse.com/security/cve/CVE-2018-5806, https://www.suse.com/security/cve/CVE-2021-3624
Affected packages
Package
Name: dcraw
Purl: pkg:rpm/opensuse/dcraw&distro=openSUSE%20Leap%2015.3
Affected ranges
Type: ECOSYSTEM
Events:
