This update for transfig fixes the following issues:
Security issue fixed:
- CVE-2018-16140: Fixed a buffer underwrite vulnerability in get_line() in
read.c, which allowed an attacker to write prior to the beginning of the
buffer via specially crafted .fig file (bsc#1106531)
This update was imported from the SUSE:SLE-15:Update update project.
Patch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 15.1:
zypper in -t patch openSUSE-2019-1455=1
- openSUSE Leap 15.0:
zypper in -t patch openSUSE-2019-1455=1
- openSUSE Leap 15.1 (x86_64):
transfig-3.2.6a-lp151.4.3.1
transfig-debuginfo-3.2.6a-lp151.4.3.1
transfig-debugsource-3.2.6a-lp151.4.3.1
- openSUSE Leap 15.0 (x86_64):
transfig-3.2.6a-lp150.3.3.2
transfig-debuginfo-3.2.6a-lp150.3.3.2
transfig-debugsource-3.2.6a-lp150.3.3.2
https://www.suse.com/security/cve/CVE-2018-16140.html
https://bugzilla.suse.com/1106531
--
Get the latest Linux and open source security news straight to your inbox.