Описание
Security update for rrdtool
This update for rrdtool fixes the following issues:
- CVE-2013-2131: Added check to the imginfo format to prevent crash or exploit (boo#828003)
- Fixed an infinite loop and crashing with pango [boo#1080251]
Список пакетов
openSUSE Leap 42.3
lua-rrdtool-1.4.7-26.3.1
python-rrdtool-1.4.7-26.3.1
rrdtool-1.4.7-26.3.1
rrdtool-cached-1.4.7-26.3.1
rrdtool-devel-1.4.7-26.3.1
ruby-rrdtool-1.4.7-26.3.1
tcl-rrdtool-1.4.7-26.3.1
Ссылки
- E-Mail link for openSUSE-SU-2018:0474-1
- SUSE Security Ratings
Описание
Format string vulnerability in the rrdtool module 1.4.7 for Python, as used in Zenoss, allows context-dependent attackers to cause a denial of service (crash) via format string specifiers to the rrdtool.graph function.
Затронутые продукты
openSUSE Leap 42.3:lua-rrdtool-1.4.7-26.3.1
openSUSE Leap 42.3:python-rrdtool-1.4.7-26.3.1
openSUSE Leap 42.3:rrdtool-1.4.7-26.3.1
openSUSE Leap 42.3:rrdtool-cached-1.4.7-26.3.1
Ссылки
- CVE-2013-2131
- SUSE Bug 828003