Описание
Security update for libxkbcommon
This update for libxkbcommon fixes the following issues:
Fixed multiple memory handling and correctness issues (bsc#1105832):
- CVE-2018-15859
- CVE-2018-15856
- CVE-2018-15858
- CVE-2018-15864
- CVE-2018-15863
- CVE-2018-15862
- CVE-2018-15861
- CVE-2018-15855
- CVE-2018-15854
- CVE-2018-15857
- CVE-2018-15853
Список пакетов
Image SLES12-SP5-Azure-SAP-BYOS
Image SLES12-SP5-Azure-SAP-On-Demand
Image SLES12-SP5-EC2-ECS-On-Demand
Image SLES12-SP5-EC2-SAP-BYOS
Image SLES12-SP5-EC2-SAP-On-Demand
Image SLES12-SP5-GCE-SAP-BYOS
Image SLES12-SP5-GCE-SAP-On-Demand
Image SLES12-SP5-SAP-Azure-LI-BYOS-Production
Image SLES12-SP5-SAP-Azure-VLI-BYOS-Production
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server for SAP Applications 12 SP5
SUSE Linux Enterprise Software Development Kit 12 SP5
Ссылки
- Link for SUSE-SU-2024:0037-1
- E-Mail link for SUSE-SU-2024:0037-1
- SUSE Security Ratings
- SUSE Bug 1105832
- SUSE CVE CVE-2018-15853 page
- SUSE CVE CVE-2018-15854 page
- SUSE CVE CVE-2018-15855 page
- SUSE CVE CVE-2018-15856 page
- SUSE CVE CVE-2018-15857 page
- SUSE CVE CVE-2018-15858 page
- SUSE CVE CVE-2018-15859 page
- SUSE CVE CVE-2018-15861 page
- SUSE CVE CVE-2018-15862 page
- SUSE CVE CVE-2018-15863 page
- SUSE CVE CVE-2018-15864 page
Описание
Endless recursion exists in xkbcomp/expr.c in xkbcommon and libxkbcommon before 0.8.1, which could be used by local attackers to crash xkbcommon users by supplying a crafted keymap file that triggers boolean negation.
Затронутые продукты
Ссылки
- CVE-2018-15853
- SUSE Bug 1105832
Описание
Unchecked NULL pointer usage in xkbcommon before 0.8.1 could be used by local attackers to crash (NULL pointer dereference) the xkbcommon parser by supplying a crafted keymap file, because geometry tokens were desupported incorrectly.
Затронутые продукты
Ссылки
- CVE-2018-15854
- SUSE Bug 1105832
Описание
Unchecked NULL pointer usage in xkbcommon before 0.8.1 could be used by local attackers to crash (NULL pointer dereference) the xkbcommon parser by supplying a crafted keymap file, because the XkbFile for an xkb_geometry section was mishandled.
Затронутые продукты
Ссылки
- CVE-2018-15855
- SUSE Bug 1105832
Описание
An infinite loop when reaching EOL unexpectedly in compose/parser.c (aka the keymap parser) in xkbcommon before 0.8.1 could be used by local attackers to cause a denial of service during parsing of crafted keymap files.
Затронутые продукты
Ссылки
- CVE-2018-15856
- SUSE Bug 1105832
Описание
An invalid free in ExprAppendMultiKeysymList in xkbcomp/ast-build.c in xkbcommon before 0.8.1 could be used by local attackers to crash xkbcommon keymap parsers or possibly have unspecified other impact by supplying a crafted keymap file.
Затронутые продукты
Ссылки
- CVE-2018-15857
- SUSE Bug 1105832
Описание
Unchecked NULL pointer usage when handling invalid aliases in CopyKeyAliasesToKeymap in xkbcomp/keycodes.c in xkbcommon before 0.8.1 could be used by local attackers to crash (NULL pointer dereference) the xkbcommon parser by supplying a crafted keymap file.
Затронутые продукты
Ссылки
- CVE-2018-15858
- SUSE Bug 1105832
Описание
Unchecked NULL pointer usage when parsing invalid atoms in ExprResolveLhs in xkbcomp/expr.c in xkbcommon before 0.8.2 could be used by local attackers to crash (NULL pointer dereference) the xkbcommon parser by supplying a crafted keymap file, because lookup failures are mishandled.
Затронутые продукты
Ссылки
- CVE-2018-15859
- SUSE Bug 1105832
Описание
Unchecked NULL pointer usage in ExprResolveLhs in xkbcomp/expr.c in xkbcommon before 0.8.2 could be used by local attackers to crash (NULL pointer dereference) the xkbcommon parser by supplying a crafted keymap file that triggers an xkb_intern_atom failure.
Затронутые продукты
Ссылки
- CVE-2018-15861
- SUSE Bug 1105832
Описание
Unchecked NULL pointer usage in LookupModMask in xkbcomp/expr.c in xkbcommon before 0.8.2 could be used by local attackers to crash (NULL pointer dereference) the xkbcommon parser by supplying a crafted keymap file with invalid virtual modifiers.
Затронутые продукты
Ссылки
- CVE-2018-15862
- SUSE Bug 1105832
Описание
Unchecked NULL pointer usage in ResolveStateAndPredicate in xkbcomp/compat.c in xkbcommon before 0.8.2 could be used by local attackers to crash (NULL pointer dereference) the xkbcommon parser by supplying a crafted keymap file with a no-op modmask expression.
Затронутые продукты
Ссылки
- CVE-2018-15863
- SUSE Bug 1105832
Описание
Unchecked NULL pointer usage in resolve_keysym in xkbcomp/parser.y in xkbcommon before 0.8.2 could be used by local attackers to crash (NULL pointer dereference) the xkbcommon parser by supplying a crafted keymap file, because a map access attempt can occur for a map that was never created.
Затронутые продукты
Ссылки
- CVE-2018-15864
- SUSE Bug 1105832