Описание
Security update for liblouis
This update for liblouis fixes the following issues:
Security issues fixed:
- CVE-2017-15101: Buffer overflow in findTable (bsc#1067336).
- CVE-2014-8184: stack-based buffer overflow in findTable() (bsc#1062458).
Список пакетов
SUSE Linux Enterprise Server 11 SP4
liblouis-1.7.0-1.3.6.1
liblouis0-1.7.0-1.3.6.1
python-louis-1.7.0-1.3.6.1
SUSE Linux Enterprise Server for SAP Applications 11 SP4
liblouis-1.7.0-1.3.6.1
liblouis0-1.7.0-1.3.6.1
python-louis-1.7.0-1.3.6.1
Ссылки
- Link for SUSE-SU-2017:3078-1
- E-Mail link for SUSE-SU-2017:3078-1
- SUSE Security Ratings
- SUSE Bug 1062458
- SUSE Bug 1067336
- SUSE CVE CVE-2014-8184 page
- SUSE CVE CVE-2017-15101 page
Описание
A vulnerability was found in liblouis, versions 2.5.x before 2.5.4. A stack-based buffer overflow was found in findTable() in liblouis. An attacker could create a malicious file that would cause applications that use liblouis (such as Orca) to crash, or potentially execute arbitrary code when opened.
Затронутые продукты
SUSE Linux Enterprise Server 11 SP4:liblouis-1.7.0-1.3.6.1
SUSE Linux Enterprise Server 11 SP4:liblouis0-1.7.0-1.3.6.1
SUSE Linux Enterprise Server 11 SP4:python-louis-1.7.0-1.3.6.1
SUSE Linux Enterprise Server for SAP Applications 11 SP4:liblouis-1.7.0-1.3.6.1
Ссылки
- CVE-2014-8184
- SUSE Bug 1056088
- SUSE Bug 1056090
- SUSE Bug 1056093
- SUSE Bug 1056095
- SUSE Bug 1056105
- SUSE Bug 1062458
- SUSE Bug 1067336
Описание
A missing patch for a stack-based buffer overflow in findTable() was found in Red Hat version of liblouis before 2.5.4. An attacker could cause a denial of service condition or potentially even arbitrary code execution.
Затронутые продукты
SUSE Linux Enterprise Server 11 SP4:liblouis-1.7.0-1.3.6.1
SUSE Linux Enterprise Server 11 SP4:liblouis0-1.7.0-1.3.6.1
SUSE Linux Enterprise Server 11 SP4:python-louis-1.7.0-1.3.6.1
SUSE Linux Enterprise Server for SAP Applications 11 SP4:liblouis-1.7.0-1.3.6.1
Ссылки
- CVE-2017-15101
- SUSE Bug 1067336