Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2020:1128-1

Опубликовано: 02 авг. 2020
Источник: suse-cvrf

Описание

Security update for libraw

This update for libraw fixes the following issues:

  • security update
  • added patches fix CVE-2020-15503 [bsc#1173674], lack of thumbnail size range check can lead to buffer overflow
    • libraw-CVE-2020-15503.patch

This update was imported from the SUSE:SLE-15:Update update project.

Список пакетов

openSUSE Leap 15.2
libraw-devel-0.18.9-lp152.5.3.1
libraw-devel-static-0.18.9-lp152.5.3.1
libraw-tools-0.18.9-lp152.5.3.1
libraw16-0.18.9-lp152.5.3.1

Описание

LibRaw before 0.20-RC1 lacks a thumbnail size range check. This affects decoders/unpack_thumb.cpp, postprocessing/mem_image.cpp, and utils/thumb_utils.cpp. For example, malloc(sizeof(libraw_processed_image_t)+T.tlength) occurs without validating T.tlength.


Затронутые продукты
openSUSE Leap 15.2:libraw-devel-0.18.9-lp152.5.3.1
openSUSE Leap 15.2:libraw-devel-static-0.18.9-lp152.5.3.1
openSUSE Leap 15.2:libraw-tools-0.18.9-lp152.5.3.1
openSUSE Leap 15.2:libraw16-0.18.9-lp152.5.3.1

Ссылки