Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2019:2319-1

Опубликовано: 16 окт. 2019
Источник: suse-cvrf

Описание

Security update for libopenmpt

This update for libopenmpt to version 0.3.19 fixes the following issues:

  • CVE-2019-17113: Fixed a buffer overflow in ModPlug_InstrumentName and ModPlug_SampleName (bsc#1153102).

This update was imported from the SUSE:SLE-15:Update update project.

Список пакетов

openSUSE Leap 15.0
libmodplug-devel-0.3.19-lp150.10.1
libmodplug1-0.3.19-lp150.10.1
libmodplug1-32bit-0.3.19-lp150.10.1
libopenmpt-devel-0.3.19-lp150.10.1
libopenmpt0-0.3.19-lp150.10.1
libopenmpt0-32bit-0.3.19-lp150.10.1
libopenmpt_modplug1-0.3.19-lp150.10.1
libopenmpt_modplug1-32bit-0.3.19-lp150.10.1
openmpt123-0.3.19-lp150.10.1

Описание

In libopenmpt before 0.3.19 and 0.4.x before 0.4.9, ModPlug_InstrumentName and ModPlug_SampleName in libopenmpt_modplug.c do not restrict the lengths of libmodplug output-buffer strings in the C API, leading to a buffer overflow.


Затронутые продукты
openSUSE Leap 15.0:libmodplug-devel-0.3.19-lp150.10.1
openSUSE Leap 15.0:libmodplug1-0.3.19-lp150.10.1
openSUSE Leap 15.0:libmodplug1-32bit-0.3.19-lp150.10.1
openSUSE Leap 15.0:libopenmpt-devel-0.3.19-lp150.10.1

Ссылки