Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2019:1200-1

Опубликовано: 12 апр. 2019
Источник: suse-cvrf

Описание

Security update for netpbm

This update for netpbm fixes the following issues:

  • CVE-2018-8975: The pm_mallocarray2 function allowed remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted image file (bsc#1086777).

This update was imported from the SUSE:SLE-15:Update update project.

Список пакетов

openSUSE Leap 15.0
libnetpbm-devel-10.80.1-lp150.2.3.1
libnetpbm11-10.80.1-lp150.2.3.1
libnetpbm11-32bit-10.80.1-lp150.2.3.1
netpbm-10.80.1-lp150.2.3.1

Описание

The pm_mallocarray2 function in lib/util/mallocvar.c in Netpbm through 10.81.03 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted image file, as demonstrated by pbmmask.


Затронутые продукты
openSUSE Leap 15.0:libnetpbm-devel-10.80.1-lp150.2.3.1
openSUSE Leap 15.0:libnetpbm11-10.80.1-lp150.2.3.1
openSUSE Leap 15.0:libnetpbm11-32bit-10.80.1-lp150.2.3.1
openSUSE Leap 15.0:netpbm-10.80.1-lp150.2.3.1

Ссылки