Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2020:0699-1

Опубликовано: 16 мар. 2020
Источник: suse-cvrf

Описание

Security update for ovmf

This update for ovmf fixes the following issues:

Security issues fixed:

  • CVE-2019-14563: Fixed a memory corruption caused by insufficient numeric truncation (bsc#1163959).
  • CVE-2019-14553: Fixed the TLS certification verification in HTTPS-over-IPv6 boot sequences (bsc#1153072).
  • CVE-2019-14559: Fixed a remotely exploitable memory leak in the ARP handling code (bsc#1163927).
  • CVE-2019-14575: Fixed an insufficient signature check in the DxeImageVerificationHandler (bsc#1163969).
  • Enabled HTTPS-over-IPv6 (bsc#1153072).

Список пакетов

SUSE Linux Enterprise Server 12 SP4
ovmf-2017+git1510945757.b2662641d5-3.23.1
ovmf-tools-2017+git1510945757.b2662641d5-3.23.1
qemu-ovmf-x86_64-2017+git1510945757.b2662641d5-3.23.1
qemu-uefi-aarch64-2017+git1510945757.b2662641d5-3.23.1
SUSE Linux Enterprise Server 12 SP5
ovmf-2017+git1510945757.b2662641d5-3.23.1
ovmf-tools-2017+git1510945757.b2662641d5-3.23.1
qemu-ovmf-x86_64-2017+git1510945757.b2662641d5-3.23.1
qemu-uefi-aarch64-2017+git1510945757.b2662641d5-3.23.1
SUSE Linux Enterprise Server for SAP Applications 12 SP4
ovmf-2017+git1510945757.b2662641d5-3.23.1
ovmf-tools-2017+git1510945757.b2662641d5-3.23.1
qemu-ovmf-x86_64-2017+git1510945757.b2662641d5-3.23.1
qemu-uefi-aarch64-2017+git1510945757.b2662641d5-3.23.1
SUSE Linux Enterprise Server for SAP Applications 12 SP5
ovmf-2017+git1510945757.b2662641d5-3.23.1
ovmf-tools-2017+git1510945757.b2662641d5-3.23.1
qemu-ovmf-x86_64-2017+git1510945757.b2662641d5-3.23.1
qemu-uefi-aarch64-2017+git1510945757.b2662641d5-3.23.1

Описание

Improper authentication in EDK II may allow a privileged user to potentially enable information disclosure via network access.


Затронутые продукты
SUSE Linux Enterprise Server 12 SP4:ovmf-2017+git1510945757.b2662641d5-3.23.1
SUSE Linux Enterprise Server 12 SP4:ovmf-tools-2017+git1510945757.b2662641d5-3.23.1
SUSE Linux Enterprise Server 12 SP4:qemu-ovmf-x86_64-2017+git1510945757.b2662641d5-3.23.1
SUSE Linux Enterprise Server 12 SP4:qemu-uefi-aarch64-2017+git1510945757.b2662641d5-3.23.1

Ссылки

Описание

Uncontrolled resource consumption in EDK II may allow an unauthenticated user to potentially enable denial of service via network access.


Затронутые продукты
SUSE Linux Enterprise Server 12 SP4:ovmf-2017+git1510945757.b2662641d5-3.23.1
SUSE Linux Enterprise Server 12 SP4:ovmf-tools-2017+git1510945757.b2662641d5-3.23.1
SUSE Linux Enterprise Server 12 SP4:qemu-ovmf-x86_64-2017+git1510945757.b2662641d5-3.23.1
SUSE Linux Enterprise Server 12 SP4:qemu-uefi-aarch64-2017+git1510945757.b2662641d5-3.23.1

Ссылки

Описание

Integer truncation in EDK II may allow an authenticated user to potentially enable escalation of privilege via local access.


Затронутые продукты
SUSE Linux Enterprise Server 12 SP4:ovmf-2017+git1510945757.b2662641d5-3.23.1
SUSE Linux Enterprise Server 12 SP4:ovmf-tools-2017+git1510945757.b2662641d5-3.23.1
SUSE Linux Enterprise Server 12 SP4:qemu-ovmf-x86_64-2017+git1510945757.b2662641d5-3.23.1
SUSE Linux Enterprise Server 12 SP4:qemu-uefi-aarch64-2017+git1510945757.b2662641d5-3.23.1

Ссылки

Описание

Logic issue in DxeImageVerificationHandler() for EDK II may allow an authenticated user to potentially enable escalation of privilege via local access.


Затронутые продукты
SUSE Linux Enterprise Server 12 SP4:ovmf-2017+git1510945757.b2662641d5-3.23.1
SUSE Linux Enterprise Server 12 SP4:ovmf-tools-2017+git1510945757.b2662641d5-3.23.1
SUSE Linux Enterprise Server 12 SP4:qemu-ovmf-x86_64-2017+git1510945757.b2662641d5-3.23.1
SUSE Linux Enterprise Server 12 SP4:qemu-uefi-aarch64-2017+git1510945757.b2662641d5-3.23.1

Ссылки