Alerts This Week
Warning Icon 1 566
Alerts This Week
Warning Icon 1 566

openSUSE 42.3: 2018:3701-2 High: libcurl Buffer Overflow

opensuse
Calendar Grey November 10, 2018
Dist Opensuse Esm H88
This Fedora Security Patch resolves 12 vulnerabilities in libpq, addressing multiple buffer overflow and denial of service flaws.
An update that solves 10 vulnerabilities and has one errata is now available.

Description

This update for opensc fixes the following issues:

- CVE-2018-16391: Fixed a denial of service when handling responses from a

Muscle Card (bsc#1106998)

- CVE-2018-16392: Fixed a denial of service when handling responses from a

TCOS Card (bsc#1106999)

- CVE-2018-16393: Fixed buffer overflows when handling responses from

Gemsafe V1 Smartcards (bsc#1108318)

- CVE-2018-16418: Fixed buffer overflow when handling string concatenation

in util_acl_to_str (bsc#1107039)

- CVE-2018-16419: Fixed several buffer overflows when handling responses

from a Cryptoflex card (bsc#1107107)

- CVE-2018-16420: Fixed buffer overflows when handling responses from an

ePass 2003 Card (bsc#1107097)

- CVE-2018-16422: Fixed single byte buffer overflow when handling

responses from an esteid Card (bsc#1107038)

- CVE-2018-16423: Fixed double free when handling responses from a

smartcard (bsc#1107037)

- CVE-2018-16426: Fixed endless recursion when...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 42.3:

zypper in -t patch openSUSE-2018-1384=1

Package List

- openSUSE Leap 42.3 (i586 x86_64):

opensc-0.13.0-9.3.1

opensc-debuginfo-0.13.0-9.3.1

opensc-debugsource-0.13.0-9.3.1

References

https://www.suse.com/security/cve/CVE-2018-16391.html

https://www.suse.com/security/cve/CVE-2018-16392.html

https://www.suse.com/security/cve/CVE-2018-16393.html

https://www.suse.com/security/cve/CVE-2018-16418.html

https://www.suse.com/security/cve/CVE-2018-16419.html

https://www.suse.com/security/cve/CVE-2018-16420.html

https://www.suse.com/security/cve/CVE-2018-16422.html

https://www.suse.com/security/cve/CVE-2018-16423.html

https://www.suse.com/security/cve/CVE-2018-16426.html

https://www.suse.com/security/cve/CVE-2018-16427.html

https://bugzilla.suse.com/1104812

https://bugzilla.suse.com/1106998

https://bugzilla.suse.com/1106999

https://bugzilla.suse.com/1107033

https://bugzilla.suse.com/1107034

https://bugzilla.suse.com/1107037

https://bugzilla.suse.com/1107038

https://bugzilla.suse.com/1107039

https://bugzilla.suse.com/1107097

https://bugzilla.suse.com/1107107

https://bugzilla.suse.com/1108318

--

Announcement ID: openSUSE-SU-2018:3701-1
Rating: moderate
Affected Products: openSUSE Leap 42.3 le.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here