Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 542
Alerts This Week
Warning Icon 1 542

SUSE: 2018:2074-1 Moderate: Libsndfile Denial of Service

suse
Calendar Grey July 26, 2018
Scroller Suse
An upgrade for libsndfile addresses three significant security vulnerabilities in SUSE Linux. Ensure you apply the most recent patch to safeguard your system.
An update that fixes three vulnerabilities is now available

Summary

This update for libsndfile fixes the following issues: Security issues fixed: - CVE-2018-13139: Fix a stack-based buffer overflow in psf_memset in common.c that allows remote attackers to cause a denial of service (bsc#1100167). - CVE-2017-17456: Prevent segmentation fault in the function d2alaw_array() that may have lead to a remote DoS (bsc#1071777) - CVE-2017-17457: Prevent segmentation fault in the function d2ulaw_array() that may have lead to a remote DoS, a different vulnerability than CVE-2017-14246 (bsc#1071767) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Basesystem 15:

References

#1071767 #1071777 #1100167

Cross- CVE-2017-17456 CVE-2017-17457 CVE-2018-13139

Affected Products:

SUSE Linux Enterprise Module for Basesystem 15

https://www.suse.com/security/cve/CVE-2017-17456.html

https://www.suse.com/security/cve/CVE-2017-17457.html

https://www.suse.com/security/cve/CVE-2018-13139.html

https://bugzilla.suse.com/1071767

https://bugzilla.suse.com/1071777

https://bugzilla.suse.com/1100167

Announcement ID: SUSE-SU-2018:2074-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.