Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2018:0474-1

Опубликовано: 19 фев. 2018
Источник: suse-cvrf

Описание

Security update for rrdtool

This update for rrdtool fixes the following issues:

  • CVE-2013-2131: Added check to the imginfo format to prevent crash or exploit (boo#828003)
  • Fixed an infinite loop and crashing with pango [boo#1080251]

Список пакетов

openSUSE Leap 42.3
lua-rrdtool-1.4.7-26.3.1
python-rrdtool-1.4.7-26.3.1
rrdtool-1.4.7-26.3.1
rrdtool-cached-1.4.7-26.3.1
rrdtool-devel-1.4.7-26.3.1
ruby-rrdtool-1.4.7-26.3.1
tcl-rrdtool-1.4.7-26.3.1

Описание

Format string vulnerability in the rrdtool module 1.4.7 for Python, as used in Zenoss, allows context-dependent attackers to cause a denial of service (crash) via format string specifiers to the rrdtool.graph function.


Затронутые продукты
openSUSE Leap 42.3:lua-rrdtool-1.4.7-26.3.1
openSUSE Leap 42.3:python-rrdtool-1.4.7-26.3.1
openSUSE Leap 42.3:rrdtool-1.4.7-26.3.1
openSUSE Leap 42.3:rrdtool-cached-1.4.7-26.3.1

Ссылки