openSUSE-SU-2019:0019-1
Dashboard / Vulnerabilities / openSUSE-SU-2019:0019-1
openSUSE-SU-2019:0019-1
Summary: Security update for discount
Details: This update for discount to version 2.2.4 fixes the following issues: Security issues fixed: - CVE-2018-11468: Fixed a heap-based buffer over-read in the __mkd_trim_line function from mkdio.c (boo#1094809) - CVE-2018-12495: Fixed a heap-based buffer over-read via a crafted file (boo#1098252)
References: https://lists.opensuse.org/archives/list/[email protected]/thread/JQ5KPQPT24VMV722GR5FUX2KOM247ZOX/#JQ5KPQPT24VMV722GR5FUX2KOM247ZOX, https://bugzilla.suse.com/1094809, https://bugzilla.suse.com/1098252, https://www.suse.com/security/cve/CVE-2018-11468, https://www.suse.com/security/cve/CVE-2018-12495
Affected packages
Package
Name: discount
Purl: pkg:rpm/suse/discount&distro=SUSE%20Package%20Hub%2015
Affected ranges
Type: ECOSYSTEM
Events:
