Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

SUSE: 2018:2469-1 Important Update for libgit2 with DoS Risks

suse
Calendar Grey August 21, 2018
Dist Suse Esm H88
SUSE has released a Security Update containing essential patches for libgit2, targeting several critical vulnerabilities and security concerns.
An update that fixes four vulnerabilities is now available

Summary

This update for libgit2 to version 0.26.5 fixes the following issues: The following security vulnerabilities were addressed: - CVE-2018-10887: Fixed an integer overflow which in turn leads to an out of bound read, allowing to read the base object, which could be exploited by an attacker to cause denial of service (DoS) (bsc#1100613). - CVE-2018-10888: Fixed an out-of-bound read while reading a binary delta file, which could be exploited by an attacker t ocause a denial of service (DoS) (bsc#1100612). - CVE-2018-11235: Fixed a remote code execution, which could occur with a crafted .gitmodules file (bsc#1095219) - CVE-2018-15501: Prevent out-of-bounds reads when processing smart-protocol "ng" packets (bsc#1104641) Patch Instructions:

References

#1095219 #1100612 #1100613 #1104641

Cross- CVE-2018-10887 CVE-2018-10888 CVE-2018-11235

CVE-2018-15501

Affected Products:

SUSE Linux Enterprise Module for Development Tools 15

https://www.suse.com/security/cve/CVE-2018-10887.html

https://www.suse.com/security/cve/CVE-2018-10888.html

https://www.suse.com/security/cve/CVE-2018-11235.html

https://www.suse.com/security/cve/CVE-2018-15501.html

https://bugzilla.suse.com/1095219

https://bugzilla.suse.com/1100612

https://bugzilla.suse.com/1100613

https://bugzilla.suse.com/1104641

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2018:2469-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here