Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2016:2242-1

Опубликовано: 05 сент. 2016
Источник: suse-cvrf

Описание

Security update for eog

This update for eog fixes the following issues:

  • Update to version 3.16.5 (boo#994819, CVE-2016-6855):
    • Bug fixes:
      • bgo#770143: CVE-2016-6855 out-of-bounds write in eog 3.10.2.
      • bgo#770197: eog leaks error message if loading an SVG fails.

Список пакетов

openSUSE Leap 42.1
eog-3.16.5-9.1
eog-devel-3.16.5-9.1
eog-lang-3.16.5-9.1

Описание

Eye of GNOME (aka eog) 3.16.5, 3.17.x, 3.18.x before 3.18.3, 3.19.x, and 3.20.x before 3.20.4, when used with glib before 2.44.1, allow remote attackers to cause a denial of service (out-of-bounds write and crash) via vectors involving passing invalid UTF-8 to GMarkup.


Затронутые продукты
openSUSE Leap 42.1:eog-3.16.5-9.1
openSUSE Leap 42.1:eog-devel-3.16.5-9.1
openSUSE Leap 42.1:eog-lang-3.16.5-9.1

Ссылки
Уязвимость openSUSE-SU-2016:2242-1