Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

SUSE: 2019:0831-1 Moderate: Libarchive Fixes Multiple Issues

suse
Calendar Grey April 1, 2019
Dist Suse Esm H88
SUSE has released a Security Update that tackles multiple vulnerabilities associated with libarchive, aimed at bolstering overall system protection with a medium priority.
An update that fixes 6 vulnerabilities is now available

Summary

This update for libarchive fixes the following issues: Security issues fixed: - CVE-2018-1000877: Fixed a double free vulnerability in RAR decoder (bsc#1120653) - CVE-2018-1000878: Fixed a Use-After-Free vulnerability in RAR decoder (bsc#1120654) - CVE-2018-1000879: Fixed a NULL Pointer Dereference vulnerability in ACL parser (bsc#1120656) - CVE-2018-1000880: Fixed an Improper Input Validation vulnerability in WARC parser (bsc#1120659) - CVE-2019-1000019: Fixed an Out-Of-Bounds Read vulnerability in 7zip decompression (bsc#1124341) - CVE-2019-1000020: Fixed an Infinite Loop vulnerability in ISO9660 parser (bsc#1124342) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".

References

#1120653 #1120654 #1120656 #1120659 #1124341

#1124342

Cross- CVE-2018-1000877 CVE-2018-1000878 CVE-2018-1000879

CVE-2018-1000880 CVE-2019-1000019 CVE-2019-1000020

Affected Products:

SUSE Linux Enterprise Module for Development Tools 15

SUSE Linux Enterprise Module for Basesystem 15

https://www.suse.com/security/cve/CVE-2018-1000877.html

https://www.suse.com/security/cve/CVE-2018-1000878.html

https://www.suse.com/security/cve/CVE-2018-1000879.html

https://www.suse.com/security/cve/CVE-2018-1000880.html

https://www.suse.com/security/cve/CVE-2019-1000019.html

https://www.suse.com/security/cve/CVE-2019-1000020.html

https://bugzilla.suse.com/1120653

https://bugzilla.suse.com/1120654

https://bugzilla.suse.com/1120656

Announcement ID: SUSE-SU-2019:0831-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here