openSUSE-SU-2019:1905-1
Dashboard / Vulnerabilities / openSUSE-SU-2019:1905-1
openSUSE-SU-2019:1905-1
Summary: Security update for dosbox
Details: This update for dosbox fixes the following issues: Security issues fixed: - CVE-2019-7165: Fixed that a very long line inside a bat file would overflow the parsing buffer (bnc#1140254). - CVE-2019-12594: Added a basic permission system so that a program running inside DOSBox can't access the contents of /proc (e.g. /proc/self/mem) when / or /proc were (to be) mounted (bnc#1140254). - Several other fixes for out of bounds access and buffer overflows.
References: https://lists.opensuse.org/archives/list/[email protected]/thread/NVX4GYW7OLUYCATD3XTOCGFTXKEEAYYP/#NVX4GYW7OLUYCATD3XTOCGFTXKEEAYYP, https://bugzilla.suse.com/1140254, https://www.suse.com/security/cve/CVE-2019-12594, https://www.suse.com/security/cve/CVE-2019-7165
Affected packages
Package
Name: dosbox
Purl: pkg:rpm/suse/dosbox&distro=SUSE%20Package%20Hub%2015
Affected ranges
Type: ECOSYSTEM
Events:
