openSUSE-SU-2019:0240-1
Dashboard / Vulnerabilities / openSUSE-SU-2019:0240-1
openSUSE-SU-2019:0240-1
Summary: Security update for pspp, spread-sheet-widget
Details: This update for pspp to version 1.2.0 fixes the following issues: Security issue fixed: - CVE-2018-20230: Fixed a heap-based buffer overflow in read_bytes_internal function that could lead to denial-of-service (bsc#1120061). Other bug fixes and changes: - Add upstream patch to avoid compiling with old Texinfo 4.13. - New experimental command SAVE DATA COLLECTION to save MDD files. - MTIME and YMDHMS variable formats now supported. - Spread sheet rendering now done via spread-sheet-widget. This update introduces a new package called spread-sheet-widget as dependency. This update was imported from the openSUSE:Leap:15.0:Update update project.
References: https://lists.opensuse.org/archives/list/[email protected]/thread/NDZXHGJWWYPHJ5EEKLF4UNQVMKTBDAKY/#NDZXHGJWWYPHJ5EEKLF4UNQVMKTBDAKY, https://bugzilla.suse.com/1120061, https://www.suse.com/security/cve/CVE-2018-20230
Affected packages
Package
Name: pspp
Purl: pkg:rpm/suse/pspp&distro=SUSE%20Package%20Hub%2015
Affected ranges
Type: ECOSYSTEM
Events:
