Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

openSUSE: 2021:1318-1 Moderate: Transfig Update for Security Fixes

opensuse
Calendar Grey September 28, 2021
Dist Opensuse Esm H88
openSUSE Security Patch for transfig addresses several critical vulnerabilities. Protect your systems promptly!
An update that fixes 5 vulnerabilities is now available

Description

This update for transfig fixes the following issues:

Update to version 3.2.8, including fixes for

- CVE-2021-3561: overflow in fig2dev/read.c in function read_colordef()

(bsc#1186329).

- CVE-2019-19797: out-of-bounds write in read_colordef in read.c

(bsc#1159293).

- CVE-2019-19555: stack-based buffer overflow because of an incorrect

sscanf (bsc#1161698).

- CVE-2019-19746: segmentation fault and out-of-bounds write because of an

integer overflow via a large arrow type (bsc#1159130).

- CVE-2019-14275: stack-based buffer overflow in the calc_arrow function

in bound.c (bsc#1143650).

This update was imported from the SUSE:SLE-15:Update update project.

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Backports SLE-15-SP3:

zypper in -t patch openSUSE-2021-1318=1

Package List

- openSUSE Backports SLE-15-SP3 (aarch64 i586 ppc64le s390x):

transfig-3.2.8a-bp153.3.3.2

References

https://www.suse.com/security/cve/CVE-2019-14275.html

https://www.suse.com/security/cve/CVE-2019-19555.html

https://www.suse.com/security/cve/CVE-2019-19746.html

https://www.suse.com/security/cve/CVE-2019-19797.html

https://www.suse.com/security/cve/CVE-2021-3561.html

https://bugzilla.suse.com/1143650

https://bugzilla.suse.com/1159130

https://bugzilla.suse.com/1159293

https://bugzilla.suse.com/1161698

https://bugzilla.suse.com/1186329

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2021:1318-1
Rating: moderate
Affected Products: openSUSE Backports SLE-15-SP3 .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here