Alerts This Week
Warning Icon 1 681
Alerts This Week
Warning Icon 1 681

SUSE: 2019:2439-1 Moderate: Rust Memory Safety and Execution Issues

suse
Calendar Grey September 23, 2019
Dist Suse Esm H88
Uncover the newest SUSE Security enhancement for Rust, targeting two major vulnerabilities with robust remediation strategies.
An update that solves two vulnerabilities and has two fixes is now available

Summary

This update for rust fixes the following issues: Rust was updated to version 1.36.0. Security issues fixed: - CVE-2019-12083: a standard method can be overridden violating Rust's safety guarantees and causing memory unsafety (bsc#1134978) - CVE-2018-1000622: rustdoc loads plugins from world writable directory allowing for arbitrary code execution (bsc#1100691) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Open Buildservice Development Tools 15: zypper in -t patch SUSE-SLE-Module-Development-Tools-OBS-15-2019-2439=1 - SUSE Linux Enterprise Module for Development Tools 15:

References

#1096945 #1100691 #1133283 #1134978

Cross- CVE-2018-1000622 CVE-2019-12083

Affected Products:

SUSE Linux Enterprise Module for Open Buildservice Development Tools 15

SUSE Linux Enterprise Module for Development Tools 15

https://www.suse.com/security/cve/CVE-2018-1000622.html

https://www.suse.com/security/cve/CVE-2019-12083.html

https://bugzilla.suse.com/1096945

https://bugzilla.suse.com/1100691

https://bugzilla.suse.com/1133283

https://bugzilla.suse.com/1134978

Announcement ID: SUSE-SU-2019:2439-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here