Описание
Security update for libostree
This update for libostree fixes the following issues:
- CVE-2014-9862: Fixed a memory corruption issue that could be triggered when diffing binary files (bsc#1201770).
Список пакетов
SUSE Linux Enterprise Module for Basesystem 15 SP4
libostree-1-1-2021.6-150400.3.3.1
SUSE Linux Enterprise Module for Desktop Applications 15 SP4
libostree-2021.6-150400.3.3.1
libostree-devel-2021.6-150400.3.3.1
typelib-1_0-OSTree-1_0-2021.6-150400.3.3.1
openSUSE Leap 15.4
libostree-2021.6-150400.3.3.1
libostree-1-1-2021.6-150400.3.3.1
libostree-devel-2021.6-150400.3.3.1
libostree-grub2-2021.6-150400.3.3.1
typelib-1_0-OSTree-1_0-2021.6-150400.3.3.1
Ссылки
- Link for SUSE-SU-2022:3094-1
- E-Mail link for SUSE-SU-2022:3094-1
- SUSE Security Ratings
- SUSE Bug 1201770
- SUSE CVE CVE-2014-9862 page
Описание
Integer signedness error in bspatch.c in bspatch in bsdiff, as used in Apple OS X before 10.11.6 and other products, allows remote attackers to execute arbitrary code or cause a denial of service (heap-based buffer overflow) via a crafted patch file.
Затронутые продукты
SUSE Linux Enterprise Module for Basesystem 15 SP4:libostree-1-1-2021.6-150400.3.3.1
SUSE Linux Enterprise Module for Desktop Applications 15 SP4:libostree-2021.6-150400.3.3.1
SUSE Linux Enterprise Module for Desktop Applications 15 SP4:libostree-devel-2021.6-150400.3.3.1
SUSE Linux Enterprise Module for Desktop Applications 15 SP4:typelib-1_0-OSTree-1_0-2021.6-150400.3.3.1
Ссылки
- CVE-2014-9862
- SUSE Bug 1173974
- SUSE Bug 1201770
- SUSE Bug 990660