Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2018:0307-1

Опубликовано: 30 янв. 2018
Источник: suse-cvrf

Описание

Security update for libapr-util1

This update for libapr-util1 fixes the following issues:

Security issue fixed:

  • CVE-2017-12618: DoS via crafted SDBM database files in apr_sdbm*() functions (bsc#1064990)

Список пакетов

SUSE Linux Enterprise Server 11 SP4
libapr-util1-1.3.4-12.22.23.3.2
libapr-util1-32bit-1.3.4-12.22.23.3.2
libapr-util1-dbd-sqlite3-1.3.4-12.22.23.3.2
SUSE Linux Enterprise Server for SAP Applications 11 SP4
libapr-util1-1.3.4-12.22.23.3.2
libapr-util1-32bit-1.3.4-12.22.23.3.2
libapr-util1-dbd-sqlite3-1.3.4-12.22.23.3.2
SUSE Linux Enterprise Software Development Kit 11 SP4
libapr-util1-1.3.4-12.22.23.3.2
libapr-util1-devel-1.3.4-12.22.23.3.2
libapr-util1-devel-32bit-1.3.4-12.22.23.3.2
SUSE Studio Onsite 1.3
libapr-util1-devel-1.3.4-12.22.23.3.2

Описание

Apache Portable Runtime Utility (APR-util) 1.6.0 and prior fail to validate the integrity of SDBM database files used by apr_sdbm*() functions, resulting in a possible out of bound read access. A local user with write access to the database can make a program or process using these functions crash, and cause a denial of service.


Затронутые продукты
SUSE Linux Enterprise Server 11 SP4:libapr-util1-1.3.4-12.22.23.3.2
SUSE Linux Enterprise Server 11 SP4:libapr-util1-32bit-1.3.4-12.22.23.3.2
SUSE Linux Enterprise Server 11 SP4:libapr-util1-dbd-sqlite3-1.3.4-12.22.23.3.2
SUSE Linux Enterprise Server for SAP Applications 11 SP4:libapr-util1-1.3.4-12.22.23.3.2

Ссылки