Описание
Security update for flex, at, libbonobo, netpbm, openslp, sgmltool, virtuoso
Various packages included vulnerable parsers generated by 'flex'.
This update provides a fixed 'flex' package and also rebuilds of packages that might have security issues caused by the auto generated code.
Flex itself was updated to fix a buffer overflow in the generated scanner (bsc#990856, CVE-2016-6354)
Packages that were rebuilt with the fixed flex:
- at
- libbonobo
- netpbm
- openslp
- sgmltool
- virtuoso
Some more packages might also need to be rebuild to receive a new flex parser, but will be released later.
This update was imported from the SUSE:SLE-12:Update update project.
Список пакетов
openSUSE Leap 42.1
Ссылки
- E-Mail link for openSUSE-SU-2016:2450-1
- SUSE Security Ratings
Описание
Heap-based buffer overflow in the yy_get_next_buffer function in Flex before 2.6.1 might allow context-dependent attackers to cause a denial of service or possibly execute arbitrary code via vectors involving num_to_read.
Затронутые продукты
Ссылки
- CVE-2016-6354
- SUSE Bug 1026047
- SUSE Bug 1035082
- SUSE Bug 1035209
- SUSE Bug 990856