Alerts This Week
Warning Icon 1 923
Alerts This Week
Warning Icon 1 923

openSUSE Leap 15.1: openSUSE-SU-2020:0163-1 Moderate: Upx Denial Of Service

opensuse
Calendar Grey February 4, 2020
Dist Opensuse Esm H88
Changes in openSUSE resolve bugs in upx: 5 security flaws patched with the release of version 3.96 improvements.
An update that fixes 5 vulnerabilities is now available.

Description

This update for upx to version 3.96 fixes the following issues:

- CVE-2019-1010048: Fixed a denial of service in

PackLinuxElf32::PackLinuxElf32help1() (boo#1141777).

- CVE-2019-14296: Fixed a denial of service in canUnpack() (boo#1143839).

- CVE-2019-20021: Fixed a heap-based buffer over-read in canUnpack()

(boo#1159833).

- CVE-2019-20053: Fixed a denial of service in canUnpack() (boo#1159920).

- CVE-2018-11243: Fixed a denial of service in PackLinuxElf64::unpack()

(boo#1094138).

- Update to version 3.96

* Bug fixes: [CVE-2019-1010048, boo#1141777] [CVE-2019-14296,

boo#1143839] [CVE-2019-20021, boo#1159833] [CVE-2019-20053,

boo#1159920] [CVE-2018-11243 partially - ticket 206 ONLY, boo#1094138]

- Update to version 3.95

* Flag --force-pie when ET_DYN main program is not marked as DF_1_PIE

* Better compatibility with varying layout of address space on Linux

* Support for 4 PT_LOAD layout in ELF generated by...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.1:

zypper in -t patch openSUSE-2020-163=1

Package List

- openSUSE Leap 15.1 (x86_64):

upx-3.96-lp151.3.3.1

upx-debuginfo-3.96-lp151.3.3.1

upx-debugsource-3.96-lp151.3.3.1

References

https://www.suse.com/security/cve/CVE-2018-11243.html

https://www.suse.com/security/cve/CVE-2019-1010048.html

https://www.suse.com/security/cve/CVE-2019-14296.html

https://www.suse.com/security/cve/CVE-2019-20021.html

https://www.suse.com/security/cve/CVE-2019-20053.html

https://bugzilla.suse.com/1094138

https://bugzilla.suse.com/1141777

https://bugzilla.suse.com/1143839

https://bugzilla.suse.com/1159833

https://bugzilla.suse.com/1159920

--

Announcement ID: openSUSE-SU-2020:0163-1
Rating: moderate
Affected Products: openSUSE Leap 15.1

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here