openSUSE-SU-2019:0345-1
Dashboard / Vulnerabilities / openSUSE-SU-2019:0345-1
openSUSE-SU-2019:0345-1
Summary: Security update for file
Details: This update for file fixes the following issues: The following security vulnerabilities were addressed: - CVE-2018-10360: Fixed an out-of-bounds read in the function do_core_note in readelf.c, which allowed remote attackers to cause a denial of service (application crash) via a crafted ELF file (bsc#1096974) - CVE-2019-8905: Fixed a stack-based buffer over-read in do_core_note in readelf.c (bsc#1126118) - CVE-2019-8906: Fixed an out-of-bounds read in do_core_note in readelf. c (bsc#1126119) - CVE-2019-8907: Fixed a stack corruption in do_core_note in readelf.c (bsc#1126117) This update was imported from the SUSE:SLE-15:Update update project.
References: https://lists.opensuse.org/archives/list/[email protected]/thread/UQQSJOBQTS7ZNXZRM4RJ7J2R4FX7TI6L/#UQQSJOBQTS7ZNXZRM4RJ7J2R4FX7TI6L, https://bugzilla.suse.com/1096974, https://bugzilla.suse.com/1096984, https://bugzilla.suse.com/1126117, https://bugzilla.suse.com/1126118, https://bugzilla.suse.com/1126119, https://www.suse.com/security/cve/CVE-2018-10360, https://www.suse.com/security/cve/CVE-2019-8905, https://www.suse.com/security/cve/CVE-2019-8906, https://www.suse.com/security/cve/CVE-2019-8907
Affected packages
Package
Name: file
Purl: pkg:rpm/opensuse/file&distro=openSUSE%20Leap%2015.0
Affected ranges
Type: ECOSYSTEM
Events:
