Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

SUSE: 2019:0926-1 Moderate: Tar Denial Of Service Issues Fixed

suse
Calendar Grey April 10, 2019
Dist Suse Esm H88
Patch released for tar addresses two critical vulnerabilities that could lead to denial of service in SUSE Linux Enterprise Modules.
An update that fixes two vulnerabilities is now available

Summary

This update for tar fixes the following issues: Security issues fixed: - CVE-2019-9923: Fixed a denial of service while parsing certain archives with malformed extended headers in pax_decode_header() (bsc#1130496). - CVE-2018-20482: Fixed a denial of service when the '--sparse' option mishandles file shrinkage during read access (bsc#1120610). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Open Buildservice Development Tools 15: zypper in -t patch SUSE-SLE-Module-Development-Tools-OBS-15-2019-926=1 - SUSE Linux Enterprise Module for Basesystem 15:

References

#1120610 #1130496

Cross- CVE-2018-20482 CVE-2019-9923

Affected Products:

SUSE Linux Enterprise Module for Open Buildservice Development Tools 15

SUSE Linux Enterprise Module for Basesystem 15

https://www.suse.com/security/cve/CVE-2018-20482.html

https://www.suse.com/security/cve/CVE-2019-9923.html

https://bugzilla.suse.com/1120610

https://bugzilla.suse.com/1130496

Announcement ID: SUSE-SU-2019:0926-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here