Описание
Security update for netpbm
This update for netpbm fixes the following issues:
- CVE-2018-8975: The pm_mallocarray2 function allowed remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted image file (bsc#1086777).
This update was imported from the SUSE:SLE-15:Update update project.
Список пакетов
openSUSE Leap 15.0
libnetpbm-devel-10.80.1-lp150.2.3.1
libnetpbm11-10.80.1-lp150.2.3.1
libnetpbm11-32bit-10.80.1-lp150.2.3.1
netpbm-10.80.1-lp150.2.3.1
Ссылки
- E-Mail link for openSUSE-SU-2019:1200-1
- SUSE Security Ratings
- SUSE Bug 1086777
- SUSE CVE CVE-2018-8975 page
Описание
The pm_mallocarray2 function in lib/util/mallocvar.c in Netpbm through 10.81.03 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted image file, as demonstrated by pbmmask.
Затронутые продукты
openSUSE Leap 15.0:libnetpbm-devel-10.80.1-lp150.2.3.1
openSUSE Leap 15.0:libnetpbm11-10.80.1-lp150.2.3.1
openSUSE Leap 15.0:libnetpbm11-32bit-10.80.1-lp150.2.3.1
openSUSE Leap 15.0:netpbm-10.80.1-lp150.2.3.1
Ссылки
- CVE-2018-8975
- SUSE Bug 1086777