openSUSE-SU-2019:2077-1
Dashboard / Vulnerabilities / openSUSE-SU-2019:2077-1
openSUSE-SU-2019:2077-1
Summary: Security update for libmirage
Details: This update for libmirage fixes the following issues: CVE-2019-15540: The CSO filter in libMirage in CDemu did not validate the part size, triggering a heap-based buffer overflow that could lead to root access by a local user. [boo#1148087] - Update to new upstream release 3.2.2 * ISO parser: fixed ISO9660/UDF pattern search for sector sizes 2332 and 2336. * ISO parser: added support for Nintendo GameCube and Wii ISO images. * Extended medium type guess to distinguish between DVD and BluRay images based on length. * Removed fabrication of disc structures from the library (moved to CDEmu daemon). * MDS parser: cleanup of disc structure parsing, fixed the incorrectly set structure sizes. This update was imported from the openSUSE:Leap:15.0:Update update project.
References: https://lists.opensuse.org/archives/list/[email protected]/thread/5RA6THTK6UZUJQU56AIXU4INYRAVL57T/#5RA6THTK6UZUJQU56AIXU4INYRAVL57T, https://bugzilla.suse.com/1148087, https://www.suse.com/security/cve/CVE-2019-15540
Affected packages
Package
Name: libmirage
Purl: pkg:rpm/suse/libmirage&distro=SUSE%20Package%20Hub%2015
Affected ranges
Type: ECOSYSTEM
Events:
