Alerts This Week
Warning Icon 1 1,394
Alerts This Week
Warning Icon 1 1,394

openSUSE Security Update 2019:0094-1 for libraw to Fix Denial of Service

opensuse
Calendar Grey January 29, 2019
Dist Opensuse Esm H88
This Fedora Security Update resolves multiple issues in libjpeg, bolstering overall system security.
An update that fixes 7 vulnerabilities is now available.

Description

This update for libraw fixes the following issues:

Security issues fixed:

- CVE-2018-20337: Fixed a stack-based buffer overflow in the

parse_makernote function of dcraw_common.cpp (bsc#1120519)

- CVE-2018-20365: Fixed a heap-based buffer overflow in the raw2image

function of libraw_cxx.cpp (bsc#1120500)

- CVE-2018-20364: Fixed a NULL pointer dereference in the copy_bayer

function of libraw_cxx.cpp (bsc#1120499)

- CVE-2018-20363: Fixed a NULL pointer dereference in the raw2image

function of libraw_cxx.cpp (bsc#1120498)

- CVE-2018-5817: Fixed an infinite loop in the unpacked_load_raw function

of dcraw_common.cpp (bsc#1120515)

- CVE-2018-5818: Fixed an infinite loop in the parse_rollei function of

dcraw_common.cpp (bsc#1120516)

- CVE-2018-5819: Fixed a denial of service in the parse_sinar_ia function

of dcraw_common.cpp (bsc#1120517)

This update was imported from the SUSE:SLE-15:Update update project.

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.0:

zypper in -t patch openSUSE-2019-94=1

Package List

- openSUSE Leap 15.0 (i586 x86_64):

libraw-debuginfo-0.18.9-lp150.2.6.1

libraw-debugsource-0.18.9-lp150.2.6.1

libraw-devel-0.18.9-lp150.2.6.1

libraw-devel-static-0.18.9-lp150.2.6.1

libraw-tools-0.18.9-lp150.2.6.1

libraw-tools-debuginfo-0.18.9-lp150.2.6.1

libraw16-0.18.9-lp150.2.6.1

libraw16-debuginfo-0.18.9-lp150.2.6.1

References

https://www.suse.com/security/cve/CVE-2018-20337.html

https://www.suse.com/security/cve/CVE-2018-20363.html

https://www.suse.com/security/cve/CVE-2018-20364.html

https://www.suse.com/security/cve/CVE-2018-20365.html

https://www.suse.com/security/cve/CVE-2018-5817.html

https://www.suse.com/security/cve/CVE-2018-5818.html

https://www.suse.com/security/cve/CVE-2018-5819.html

https://bugzilla.suse.com/1120498

https://bugzilla.suse.com/1120499

https://bugzilla.suse.com/1120500

https://bugzilla.suse.com/1120515

https://bugzilla.suse.com/1120516

https://bugzilla.suse.com/1120517

https://bugzilla.suse.com/1120519

--

Announcement ID: openSUSE-SU-2019:0094-1
Rating: moderate
Affected Products: openSUSE Leap 15.0

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here