Alerts This Week
Warning Icon 1 684
Alerts This Week
Warning Icon 1 684

openSUSE Leap 15.3: 2021:2937-1 Important: Libesmtp Buffer Over-Read

opensuse
Calendar Grey September 3, 2021
Dist Opensuse Esm H88
A crucial patch is ready for libesmtp on openSUSE. It resolves a buffer over-read issue and mitigates potential vulnerabilities.
An update that solves one vulnerability and has one errata is now available

Description

This update for libesmtp fixes the following issues:

- CVE-2019-19977: Fixed stack-based buffer over-read in ntlm/ntlmstruct.c

(bsc#1160462).

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.3:

zypper in -t patch openSUSE-SLE-15.3-2021-2937=1

Package List

- openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64):

libesmtp-1.0.6-150.4.1

libesmtp-debuginfo-1.0.6-150.4.1

libesmtp-debugsource-1.0.6-150.4.1

libesmtp-devel-1.0.6-150.4.1

References

https://www.suse.com/security/cve/CVE-2019-19977.html

https://bugzilla.suse.com/1160462

https://bugzilla.suse.com/1189097

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2021:2937-1
Rating: important
Affected Products: openSUSE Leap 15.3 ble.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here