Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

openSUSE: 2019:2077-1 Moderate: libmirage Heap Overflow Threat

opensuse
Calendar Grey September 6, 2019
Dist Opensuse Esm H88
Critical patch for openSUSE tackling a buffer overflow in libmirage. Apply this update to boost your system's security and overall performance.
An update that fixes one vulnerability is now available.

Description

This update for libmirage fixes the following issues:

CVE-2019-15540: The CSO filter in libMirage in CDemu did not validate the

part size, triggering a heap-based buffer overflow that could lead to root

access by a local user. [boo#1148087]

- Update to new upstream release 3.2.2

* ISO parser: fixed ISO9660/UDF pattern search for sector sizes 2332 and

2336.

* ISO parser: added support for Nintendo GameCube and Wii ISO images.

* Extended medium type guess to distinguish between DVD and BluRay

images based on length.

* Removed fabrication of disc structures from the library (moved to

CDEmu daemon).

* MDS parser: cleanup of disc structure parsing, fixed the incorrectly

set structure sizes.

This update was imported from the openSUSE:Leap:15.0:Update update project.

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Backports SLE-15-SP1:

zypper in -t patch openSUSE-2019-2077=1

- openSUSE Backports SLE-15:

zypper in -t patch openSUSE-2019-2077=1

Package List

- openSUSE Backports SLE-15-SP1 (aarch64 ppc64le s390x x86_64):

libmirage-3_2-3.2.2-bp151.4.3.1

libmirage-3_2-debuginfo-3.2.2-bp151.4.3.1

libmirage-debuginfo-3.2.2-bp151.4.3.1

libmirage-debugsource-3.2.2-bp151.4.3.1

libmirage-devel-3.2.2-bp151.4.3.1

libmirage11-3.2.2-bp151.4.3.1

libmirage11-debuginfo-3.2.2-bp151.4.3.1

typelib-1_0-libmirage-3_2-3.2.2-bp151.4.3.1

- openSUSE Backports SLE-15-SP1 (noarch):

libmirage-data-3.2.2-bp151.4.3.1

libmirage-lang-3.2.2-bp151.4.3.1

- openSUSE Backports SLE-15 (aarch64 ppc64le s390x x86_64):

libmirage-3_2-3.2.2-bp150.3.3.1

libmirage-devel-3.2.2-bp150.3.3.1

libmirage11-3.2.2-bp150.3.3.1

typelib-1_0-libmirage-3_2-3.2.2-bp150.3.3.1

- openSUSE Backports SLE-15 (noarch):

libmirage-data-3.2.2-bp150.3.3.1

libmirage-lang-3.2.2-bp150.3.3.1

References

https://www.suse.com/security/cve/CVE-2019-15540.html

https://bugzilla.suse.com/1148087

--

Announcement ID: openSUSE-SU-2019:2077-1
Rating: moderate
Affected Products: openSUSE Backports SLE-15-SP1 openSUSE Backports SLE-15

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here