Описание
Security update for ncurses
This update for ncurses fixes the following issues:
Security issues fixed:
- CVE-2017-13728: Fix infinite loop in the next_char function in comp_scan.c (bsc#1056136).
- CVE-2017-13730: Fix illegal address access in the function _nc_read_entry_source() (bsc#1056131).
- CVE-2017-13733: Fix illegal address access in the fmt_entry function (bsc#1056127).
- CVE-2017-13729: Fix illegal address access in the _nc_save_str (bsc#1056132).
- CVE-2017-13732: Fix illegal address access in the function dump_uses() (bsc#1056128).
- CVE-2017-13731: Fix illegal address access in the function postprocess_termcap() (bsc#1056129).
Список пакетов
SUSE Linux Enterprise Desktop 12 SP2
SUSE Linux Enterprise Desktop 12 SP3
SUSE Linux Enterprise Server 12 SP2
SUSE Linux Enterprise Server 12 SP3
SUSE Linux Enterprise Server for Raspberry Pi 12 SP2
SUSE Linux Enterprise Server for SAP Applications 12 SP2
SUSE Linux Enterprise Server for SAP Applications 12 SP3
SUSE Linux Enterprise Software Development Kit 12 SP2
SUSE Linux Enterprise Software Development Kit 12 SP3
Ссылки
- Link for SUSE-SU-2018:0120-1
- E-Mail link for SUSE-SU-2018:0120-1
- SUSE Security Ratings
- SUSE Bug 1056127
- SUSE Bug 1056128
- SUSE Bug 1056129
- SUSE Bug 1056131
- SUSE Bug 1056132
- SUSE Bug 1056136
- SUSE CVE CVE-2017-13728 page
- SUSE CVE CVE-2017-13729 page
- SUSE CVE CVE-2017-13730 page
- SUSE CVE CVE-2017-13731 page
- SUSE CVE CVE-2017-13732 page
- SUSE CVE CVE-2017-13733 page
Описание
There is an infinite loop in the next_char function in comp_scan.c in ncurses 6.0, related to libtic. A crafted input will lead to a remote denial of service attack.
Затронутые продукты
Ссылки
- CVE-2017-13728
- SUSE Bug 1056136
- SUSE Bug 1069530
- SUSE Bug 1115932
- SUSE Bug 1123132
- SUSE Bug 1175501
Описание
There is an illegal address access in the _nc_save_str function in alloc_entry.c in ncurses 6.0. It will lead to a remote denial of service attack.
Затронутые продукты
Ссылки
- CVE-2017-13729
- SUSE Bug 1056132
- SUSE Bug 1069530
- SUSE Bug 1115932
- SUSE Bug 1123132
- SUSE Bug 1175501
Описание
There is an illegal address access in the function _nc_read_entry_source() in progs/tic.c in ncurses 6.0 that might lead to a remote denial of service attack.
Затронутые продукты
Ссылки
- CVE-2017-13730
- SUSE Bug 1056131
- SUSE Bug 1069530
- SUSE Bug 1115932
- SUSE Bug 1123132
- SUSE Bug 1175501
Описание
There is an illegal address access in the function postprocess_termcap() in parse_entry.c in ncurses 6.0 that will lead to a remote denial of service attack.
Затронутые продукты
Ссылки
- CVE-2017-13731
- SUSE Bug 1056129
- SUSE Bug 1069530
- SUSE Bug 1115932
- SUSE Bug 1123132
- SUSE Bug 1175501
Описание
There is an illegal address access in the function dump_uses() in progs/dump_entry.c in ncurses 6.0 that might lead to a remote denial of service attack.
Затронутые продукты
Ссылки
- CVE-2017-13732
- SUSE Bug 1056128
- SUSE Bug 1069530
- SUSE Bug 1115932
- SUSE Bug 1123132
- SUSE Bug 1175501
Описание
There is an illegal address access in the fmt_entry function in progs/dump_entry.c in ncurses 6.0 that might lead to a remote denial of service attack.
Затронутые продукты
Ссылки
- CVE-2017-13733
- SUSE Bug 1056127
- SUSE Bug 1069530
- SUSE Bug 1115932
- SUSE Bug 1123132
- SUSE Bug 1175501