Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 464
Alerts This Week
Warning Icon 1 464

SUSE: 2016:1909-1 Important: Libarchive Heap Overflow - Heap Buffer Issue

suse
Calendar Grey July 29, 2016
Scroller Suse
Resolves 20 vulnerabilities in SUSE libarchive, critical patch released for multiple offerings.
An update that fixes 20 vulnerabilities is now available

Summary

libarchive was updated to fix 20 security issues. These security issues were fixed: - CVE-2015-8918: Overlapping memcpy in CAB parser (bsc#985698). - CVE-2015-8919: Heap out of bounds read in LHA/LZH parser (bsc#985697). - CVE-2015-8920: Stack out of bounds read in ar parser (bsc#985675). - CVE-2015-8921: Global out of bounds read in mtree parser (bsc#985682). - CVE-2015-8922: Null pointer access in 7z parser (bsc#985685). - CVE-2015-8923: Unclear crashes in ZIP parser (bsc#985703). - CVE-2015-8924: Heap buffer read overflow in tar (bsc#985609). - CVE-2015-8925: Unclear invalid memory read in mtree parser (bsc#985706). - CVE-2015-8926: NULL pointer access in RAR parser (bsc#985704). - CVE-2015-8928: Heap out of bounds read in mtree parser (bsc#985679).

References

#984990 #985609 #985665 #985669 #985673 #985675

#985679 #985682 #985685 #985688 #985689 #985697

#985698 #985700 #985703 #985704 #985706 #985826

#985832 #985835

Cross- CVE-2015-8918 CVE-2015-8919 CVE-2015-8920

CVE-2015-8921 CVE-2015-8922 CVE-2015-8923

CVE-2015-8924 CVE-2015-8925 CVE-2015-8926

CVE-2015-8928 CVE-2015-8929 CVE-2015-8930

CVE-2015-8931 CVE-2015-8932 CVE-2015-8933

CVE-2015-8934 CVE-2016-4300 CVE-2016-4301

CVE-2016-4302 CVE-2016-4809

Affected Products:

SUSE Linux Enterprise Software Development Kit 12-SP1

SUSE Linux Enterprise Server 12-SP1

SUSE Linux Enterprise Desktop 12-SP1

https://www.suse.com/security/cve/CVE-2015-8918.html

https://www.suse.com/security/cve/CVE-2015-8919.html

https://www.suse.com/security/cve/CVE-2015-8920.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2016:1909-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.