Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2018:4207-1

Опубликовано: 20 дек. 2018
Источник: suse-cvrf

Описание

Security update for ovmf

This update for ovmf fixes the following issues:

Security issues fixed:

  • CVE-2018-3613: Fixed AuthVariable Timestamp zeroing issue on APPEND_WRITE (bsc#1115916).
  • CVE-2017-5731: Fixed privilege escalation via processing of malformed files in TianoCompress.c (bsc#1115917).
  • CVE-2017-5732: Fixed privilege escalation via processing of malformed files in BaseUefiDecompressLib.c (bsc#1115917).
  • CVE-2017-5733: Fixed privilege escalation via heap-based buffer overflow in MakeTable() function (bsc#1115917).
  • CVE-2017-5734: Fixed privilege escalation via stack-based buffer overflow in MakeTable() function (bsc#1115917).
  • CVE-2017-5735: Fixed privilege escalation via heap-based buffer overflow in Decode() function (bsc#1115917).

Список пакетов

SUSE Linux Enterprise Server 12 SP3
ovmf-2017+git1492060560.b6d11d7c46-4.17.1
ovmf-tools-2017+git1492060560.b6d11d7c46-4.17.1
qemu-ovmf-x86_64-2017+git1492060560.b6d11d7c46-4.17.1
qemu-uefi-aarch64-2017+git1492060560.b6d11d7c46-4.17.1
SUSE Linux Enterprise Server for SAP Applications 12 SP3
ovmf-2017+git1492060560.b6d11d7c46-4.17.1
ovmf-tools-2017+git1492060560.b6d11d7c46-4.17.1
qemu-ovmf-x86_64-2017+git1492060560.b6d11d7c46-4.17.1
qemu-uefi-aarch64-2017+git1492060560.b6d11d7c46-4.17.1

Описание

Bounds checking in Tianocompress before November 7, 2017 may allow an authenticated user to potentially enable an escalation of privilege via local access.


Затронутые продукты
SUSE Linux Enterprise Server 12 SP3:ovmf-2017+git1492060560.b6d11d7c46-4.17.1
SUSE Linux Enterprise Server 12 SP3:ovmf-tools-2017+git1492060560.b6d11d7c46-4.17.1
SUSE Linux Enterprise Server 12 SP3:qemu-ovmf-x86_64-2017+git1492060560.b6d11d7c46-4.17.1
SUSE Linux Enterprise Server 12 SP3:qemu-uefi-aarch64-2017+git1492060560.b6d11d7c46-4.17.1

Ссылки

Описание

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none.


Затронутые продукты
SUSE Linux Enterprise Server 12 SP3:ovmf-2017+git1492060560.b6d11d7c46-4.17.1
SUSE Linux Enterprise Server 12 SP3:ovmf-tools-2017+git1492060560.b6d11d7c46-4.17.1
SUSE Linux Enterprise Server 12 SP3:qemu-ovmf-x86_64-2017+git1492060560.b6d11d7c46-4.17.1
SUSE Linux Enterprise Server 12 SP3:qemu-uefi-aarch64-2017+git1492060560.b6d11d7c46-4.17.1

Ссылки

Описание

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none.


Затронутые продукты
SUSE Linux Enterprise Server 12 SP3:ovmf-2017+git1492060560.b6d11d7c46-4.17.1
SUSE Linux Enterprise Server 12 SP3:ovmf-tools-2017+git1492060560.b6d11d7c46-4.17.1
SUSE Linux Enterprise Server 12 SP3:qemu-ovmf-x86_64-2017+git1492060560.b6d11d7c46-4.17.1
SUSE Linux Enterprise Server 12 SP3:qemu-uefi-aarch64-2017+git1492060560.b6d11d7c46-4.17.1

Ссылки

Описание

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none.


Затронутые продукты
SUSE Linux Enterprise Server 12 SP3:ovmf-2017+git1492060560.b6d11d7c46-4.17.1
SUSE Linux Enterprise Server 12 SP3:ovmf-tools-2017+git1492060560.b6d11d7c46-4.17.1
SUSE Linux Enterprise Server 12 SP3:qemu-ovmf-x86_64-2017+git1492060560.b6d11d7c46-4.17.1
SUSE Linux Enterprise Server 12 SP3:qemu-uefi-aarch64-2017+git1492060560.b6d11d7c46-4.17.1

Ссылки

Описание

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none.


Затронутые продукты
SUSE Linux Enterprise Server 12 SP3:ovmf-2017+git1492060560.b6d11d7c46-4.17.1
SUSE Linux Enterprise Server 12 SP3:ovmf-tools-2017+git1492060560.b6d11d7c46-4.17.1
SUSE Linux Enterprise Server 12 SP3:qemu-ovmf-x86_64-2017+git1492060560.b6d11d7c46-4.17.1
SUSE Linux Enterprise Server 12 SP3:qemu-uefi-aarch64-2017+git1492060560.b6d11d7c46-4.17.1

Ссылки

Описание

Logic issue in variable service module for EDK II/UDK2018/UDK2017/UDK2015 may allow an authenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via local access.


Затронутые продукты
SUSE Linux Enterprise Server 12 SP3:ovmf-2017+git1492060560.b6d11d7c46-4.17.1
SUSE Linux Enterprise Server 12 SP3:ovmf-tools-2017+git1492060560.b6d11d7c46-4.17.1
SUSE Linux Enterprise Server 12 SP3:qemu-ovmf-x86_64-2017+git1492060560.b6d11d7c46-4.17.1
SUSE Linux Enterprise Server 12 SP3:qemu-uefi-aarch64-2017+git1492060560.b6d11d7c46-4.17.1

Ссылки
Уязвимость SUSE-SU-2018:4207-1