Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 514
Alerts This Week
Warning Icon 1 514

SUSE: 2018:1972-1 Critical: Perl Security Update with Multiple Fixes

suse
Calendar Grey July 17, 2018
Scroller Suse
SUSE patches tackle several key vulnerabilities in perl. Apply the updates promptly to enhance system security.
An update that solves four vulnerabilities and has one errata is now available

Summary

This update for perl fixes the following issues: These security issue were fixed: - CVE-2018-6913: Fixed space calculation issues in pp_pack.c (bsc#1082216). - CVE-2018-6798: Fixed heap buffer overflow in regexec.c (bsc#1082233). - CVE-2018-6797: Fixed sharp-s regexp overflow (bsc#1082234). - CVE-2018-12015: The Archive::Tar module allowed remote attackers to bypass a directory-traversal protection mechanism and overwrite arbitrary files (bsc#1096718) This non-security issue was fixed: - fix debugger crash in tab completion with Term::ReadLine::Gnu [bsc#1068565] Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE OpenStack Cloud 7:

References

#1068565 #1082216 #1082233 #1082234 #1096718

Cross- CVE-2018-12015 CVE-2018-6797 CVE-2018-6798

CVE-2018-6913

Affected Products:

SUSE OpenStack Cloud 7

SUSE Linux Enterprise Server for SAP 12-SP2

SUSE Linux Enterprise Server for SAP 12-SP1

SUSE Linux Enterprise Server 12-SP3

SUSE Linux Enterprise Server 12-SP2-LTSS

SUSE Linux Enterprise Server 12-SP1-LTSS

SUSE Linux Enterprise Server 12-LTSS

SUSE Linux Enterprise Desktop 12-SP3

SUSE Enterprise Storage 4

SUSE CaaS Platform ALL

OpenStack Cloud Magnum Orchestration 7

https://www.suse.com/security/cve/CVE-2018-12015.html

https://www.suse.com/security/cve/CVE-2018-6797.html

https://www.suse.com/security/cve/CVE-2018-6798.html

https://www.suse.com/security/cve/CVE-2018-6913.html

...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2018:1972-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.