Описание
Security update for netpbm
This update for netpbm fixes the following issues:
- CVE-2018-8975: The pm_mallocarray2 function allowed remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted image file (bsc#1086777).
Список пакетов
SUSE Linux Enterprise Module for Basesystem 15
libnetpbm11-10.80.1-3.3.36
netpbm-10.80.1-3.3.36
SUSE Linux Enterprise Module for Desktop Applications 15
libnetpbm-devel-10.80.1-3.3.36
Ссылки
- Link for SUSE-SU-2019:0855-1
- E-Mail link for SUSE-SU-2019:0855-1
- SUSE Security Ratings
- SUSE Bug 1086777
- SUSE CVE CVE-2018-8975 page
Описание
The pm_mallocarray2 function in lib/util/mallocvar.c in Netpbm through 10.81.03 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted image file, as demonstrated by pbmmask.
Затронутые продукты
SUSE Linux Enterprise Module for Basesystem 15:libnetpbm11-10.80.1-3.3.36
SUSE Linux Enterprise Module for Basesystem 15:netpbm-10.80.1-3.3.36
SUSE Linux Enterprise Module for Desktop Applications 15:libnetpbm-devel-10.80.1-3.3.36
Ссылки
- CVE-2018-8975
- SUSE Bug 1086777