Описание
Security update for ovmf
This update for ovmf fixes the following issue:
Security issue fixed:
- CVE-2018-12181: Fixed a stack buffer overflow in the HII database when a corrupted Bitmap was used (bsc#1128503).
Список пакетов
SUSE Linux Enterprise Server 12 SP3
ovmf-2017+git1492060560.b6d11d7c46-4.23.1
ovmf-tools-2017+git1492060560.b6d11d7c46-4.23.1
qemu-ovmf-x86_64-2017+git1492060560.b6d11d7c46-4.23.1
qemu-uefi-aarch64-2017+git1492060560.b6d11d7c46-4.23.1
SUSE Linux Enterprise Server for SAP Applications 12 SP3
ovmf-2017+git1492060560.b6d11d7c46-4.23.1
ovmf-tools-2017+git1492060560.b6d11d7c46-4.23.1
qemu-ovmf-x86_64-2017+git1492060560.b6d11d7c46-4.23.1
qemu-uefi-aarch64-2017+git1492060560.b6d11d7c46-4.23.1
Ссылки
- Link for SUSE-SU-2019:0738-1
- E-Mail link for SUSE-SU-2019:0738-1
- SUSE Security Ratings
- SUSE Bug 1128503
- SUSE CVE CVE-2018-12181 page
Описание
Stack overflow in corrupted bmp for EDK II may allow unprivileged user to potentially enable denial of service or elevation of privilege via local access.
Затронутые продукты
SUSE Linux Enterprise Server 12 SP3:ovmf-2017+git1492060560.b6d11d7c46-4.23.1
SUSE Linux Enterprise Server 12 SP3:ovmf-tools-2017+git1492060560.b6d11d7c46-4.23.1
SUSE Linux Enterprise Server 12 SP3:qemu-ovmf-x86_64-2017+git1492060560.b6d11d7c46-4.23.1
SUSE Linux Enterprise Server 12 SP3:qemu-uefi-aarch64-2017+git1492060560.b6d11d7c46-4.23.1
Ссылки
- CVE-2018-12181
- SUSE Bug 1128503