Alerts This Week
Warning Icon 1 535
Alerts This Week
Warning Icon 1 535

SUSE: 2019:0839-1 Moderate: File Denial of Service Threat

suse
Calendar Grey April 2, 2019
Dist Suse Esm H88
An update resolves four moderate-severity vulnerabilities in the SUSE system files. A patch is now available for the impacted distributions and platforms.
An update that solves four vulnerabilities and has one errata is now available

Summary

This update for file fixes the following issues: The following security vulnerabilities were addressed: - Fixed an out-of-bounds read in the function do_core_note in readelf.c, which allowed remote attackers to cause a denial of service (application crash) via a crafted ELF file (bsc#1096974 CVE-2018-10360). - CVE-2019-8905: Fixed a stack-based buffer over-read in do_core_note in readelf.c (bsc#1126118) - CVE-2019-8906: Fixed an out-of-bounds read in do_core_note in readelf. c (bsc#1126119) - CVE-2019-8907: Fixed a stack corruption in do_core_note in readelf.c (bsc#1126117) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product:

References

#1096974 #1096984 #1126117 #1126118 #1126119

Cross- CVE-2018-10360 CVE-2019-8905 CVE-2019-8906

CVE-2019-8907

Affected Products:

SUSE Linux Enterprise Software Development Kit 12-SP4

SUSE Linux Enterprise Software Development Kit 12-SP3

SUSE Linux Enterprise Server 12-SP4

SUSE Linux Enterprise Server 12-SP3

SUSE Linux Enterprise Desktop 12-SP4

SUSE Linux Enterprise Desktop 12-SP3

SUSE CaaS Platform ALL

SUSE CaaS Platform 3.0

OpenStack Cloud Magnum Orchestration 7

https://www.suse.com/security/cve/CVE-2018-10360.html

https://www.suse.com/security/cve/CVE-2019-8905.html

https://www.suse.com/security/cve/CVE-2019-8906.html

https://www.suse.com/security/cve/CVE-2019-8907.html

https://bugzilla.suse.com/1096974

https://bugzilla.suse.com/1096984

Announcement ID: SUSE-SU-2019:0839-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here