Описание
Security update for netpbm
This update for netpbm fixes the following issues:
Security issues fixed:
-
CVE-2018-8975: The pm_mallocarray2 function allowed remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted image file (bsc#1086777).
-
CVE-2017-2579: Fixed out-of-bounds read in expandCodeOntoStack() (bsc#1024288).
-
CVE-2017-2580: Fixed out-of-bounds write of heap data in addPixelToRaster() function (bsc#1024291).
-
create netpbm-vulnerable subpackage and move pstopnm there (bsc#1136936)
Список пакетов
SUSE Linux Enterprise Desktop 12 SP3
SUSE Linux Enterprise Desktop 12 SP4
SUSE Linux Enterprise Server 12 SP3
SUSE Linux Enterprise Server 12 SP4
SUSE Linux Enterprise Server for SAP Applications 12 SP3
SUSE Linux Enterprise Server for SAP Applications 12 SP4
SUSE Linux Enterprise Software Development Kit 12 SP3
SUSE Linux Enterprise Software Development Kit 12 SP4
Ссылки
- Link for SUSE-SU-2019:1645-1
- E-Mail link for SUSE-SU-2019:1645-1
- SUSE Security Ratings
- SUSE Bug 1024288
- SUSE Bug 1024291
- SUSE Bug 1086777
- SUSE Bug 1136936
- SUSE CVE CVE-2017-2579 page
- SUSE CVE CVE-2017-2580 page
- SUSE CVE CVE-2018-8975 page
Описание
An out-of-bounds read vulnerability was found in netpbm before 10.61. The expandCodeOntoStack() function has an insufficient code value check, so that a maliciously crafted file could cause the application to crash or possibly allows code execution.
Затронутые продукты
Ссылки
- CVE-2017-2579
- SUSE Bug 1024287
- SUSE Bug 1024288
Описание
An out-of-bounds write vulnerability was found in netpbm before 10.61. A maliciously crafted file could cause the application to crash or possibly allow code execution.
Затронутые продукты
Ссылки
- CVE-2017-2580
- SUSE Bug 1024287
- SUSE Bug 1024291
Описание
The pm_mallocarray2 function in lib/util/mallocvar.c in Netpbm through 10.81.03 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted image file, as demonstrated by pbmmask.
Затронутые продукты
Ссылки
- CVE-2018-8975
- SUSE Bug 1086777