Описание
Security update for xar
This update for xar fixes the following issues:
Changes in xar:
- Switch to the maintained Apple xar lineage (build 503, versioned
1.8.0.0.503): the mackyle 1.6.1 fork this package tracked has been
dead since 2012, and Debian, Fedora and Gentoo all moved to Apple's
xar (apple-oss-distributions/xar). This resolves the long-standing
NULL-pointer dereferences in xar_get_path() and xar_unserialize()
when parsing malformed archives:
- CVE-2017-11124 (boo#1047875)
- CVE-2017-11125 (boo#1047874)
- CVE-2018-17093 (boo#1108595)
- CVE-2018-17094 (boo#1108596)
Список пакетов
openSUSE Leap 16.0
Ссылки
- SUSE Security Ratings
- SUSE Bug 1047874
- SUSE Bug 1047875
- SUSE Bug 1108595
- SUSE Bug 1108596
- SUSE CVE CVE-2017-11124 page
- SUSE CVE CVE-2017-11125 page
- SUSE CVE CVE-2018-17093 page
- SUSE CVE CVE-2018-17094 page
Описание
libxar.so in xar 1.6.1 has a NULL pointer dereference in the xar_unserialize function in archive.c.
Затронутые продукты
Ссылки
- CVE-2017-11124
- SUSE Bug 1047875
Описание
libxar.so in xar 1.6.1 has a NULL pointer dereference in the xar_get_path function in util.c.
Затронутые продукты
Ссылки
- CVE-2017-11125
- SUSE Bug 1047874
Описание
DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-11125. Reason: This candidate is a duplicate of CVE-2017-11125. Notes: All CVE users should reference CVE-2017-11125 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage
Затронутые продукты
Ссылки
- CVE-2018-17093
- SUSE Bug 1108595
Описание
DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-11124. Reason: This candidate is a duplicate of CVE-2017-11124. Notes: All CVE users should reference CVE-2017-11124 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage
Затронутые продукты
Ссылки
- CVE-2018-17094
- SUSE Bug 1108596