Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2022:3671-1

Опубликовано: 20 окт. 2022
Источник: suse-cvrf

Описание

Security update for libostree

This update for libostree fixes the following issues:

  • CVE-2014-9862: Fixed arbitrary write on heap vulnerability (bsc#1201770).

Список пакетов

SUSE Linux Enterprise High Performance Computing 15-ESPOS
libostree-2018.1-150000.4.3.1
libostree-1-1-2018.1-150000.4.3.1
libostree-devel-2018.1-150000.4.3.1
typelib-1_0-OSTree-1_0-2018.1-150000.4.3.1
SUSE Linux Enterprise High Performance Computing 15-LTSS
libostree-2018.1-150000.4.3.1
libostree-1-1-2018.1-150000.4.3.1
libostree-devel-2018.1-150000.4.3.1
typelib-1_0-OSTree-1_0-2018.1-150000.4.3.1
SUSE Linux Enterprise Server 15-LTSS
libostree-2018.1-150000.4.3.1
libostree-1-1-2018.1-150000.4.3.1
libostree-devel-2018.1-150000.4.3.1
typelib-1_0-OSTree-1_0-2018.1-150000.4.3.1
SUSE Linux Enterprise Server for SAP Applications 15
libostree-2018.1-150000.4.3.1
libostree-1-1-2018.1-150000.4.3.1
libostree-devel-2018.1-150000.4.3.1
typelib-1_0-OSTree-1_0-2018.1-150000.4.3.1

Описание

Integer signedness error in bspatch.c in bspatch in bsdiff, as used in Apple OS X before 10.11.6 and other products, allows remote attackers to execute arbitrary code or cause a denial of service (heap-based buffer overflow) via a crafted patch file.


Затронутые продукты
SUSE Linux Enterprise High Performance Computing 15-ESPOS:libostree-1-1-2018.1-150000.4.3.1
SUSE Linux Enterprise High Performance Computing 15-ESPOS:libostree-2018.1-150000.4.3.1
SUSE Linux Enterprise High Performance Computing 15-ESPOS:libostree-devel-2018.1-150000.4.3.1
SUSE Linux Enterprise High Performance Computing 15-ESPOS:typelib-1_0-OSTree-1_0-2018.1-150000.4.3.1

Ссылки