Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

openSUSE 42.3: 2018:0570-1 Important: freexl Heap Overflow Issue

opensuse
Calendar Grey March 1, 2018
Dist Opensuse Esm H88
A crucial security patch for openSUSE freexl addresses 5 severe vulnerabilities. Find patch specifics and upgrade guidelines here.
An update that fixes 5 vulnerabilities is now available.

Description

This update for freexl fixes the following issues:

freexl was updated to version 1.0.5:

* No changelog provided by upstream

* Various heapoverflows in 1.0.4 have been fixed:

* CVE-2018-7439: heap-buffer-overflow in freexl.c:3912

read_mini_biff_next_record (boo#1082774)

* CVE-2018-7438: heap-buffer-overflow in freexl.c:383

parse_unicode_string (boo#1082775)

* CVE-2018-7437: heap-buffer-overflow in freexl.c:1866

parse_SST(boo#1082776)

* CVE-2018-7436: heap-buffer-overflow in freexl.c:1805 parse_SST

parse_SST (boo#1082777)

* CVE-2018-7435: heap-buffer-overflow in freexl::destroy_cell

(boo#1082778)

Patch

Patch Instructions:

To install this openSUSE Security Update use YaST online_update.

Alternatively you can run the command listed for your product:

- openSUSE Leap 42.3:

zypper in -t patch openSUSE-2018-217=1

To bring your system up-to-date, use "zypper patch".

Package List

- openSUSE Leap 42.3 (i586 x86_64):

freexl-debugsource-1.0.5-8.1

freexl-devel-1.0.5-8.1

libfreexl1-1.0.5-8.1

libfreexl1-debuginfo-1.0.5-8.1

References

https://www.suse.com/security/cve/CVE-2018-7435.html

https://www.suse.com/security/cve/CVE-2018-7436.html

https://www.suse.com/security/cve/CVE-2018-7437.html

https://www.suse.com/security/cve/CVE-2018-7438.html

https://www.suse.com/security/cve/CVE-2018-7439.html

https://bugzilla.suse.com/1082774

https://bugzilla.suse.com/1082775

https://bugzilla.suse.com/1082776

https://bugzilla.suse.com/1082777

https://bugzilla.suse.com/1082778

--

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2018:0570-1
Rating: important
Affected Products: openSUSE Leap 42.3

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here