Alerts This Week
Warning Icon 1 681
Alerts This Week
Warning Icon 1 681

SUSE: 2019:3094-1 Moderate: ncurses Denial Of Service and Buffer Over-Read

suse
Calendar Grey November 28, 2019
Dist Suse Esm H88
A security patch from SUSE for gdb resolves several flaws, enhancing the protection of systems in numerous distributions.
An update that solves three vulnerabilities and has one errata is now available

Summary

This update for ncurses fixes the following issues: Security issue fixed: - CVE-2018-10754: Fixed a denial of service caused by a NULL Pointer Dereference in the _nc_parse_entry() (bsc#1131830). - CVE-2019-17594: Fixed a heap-based buffer over-read in _nc_find_entry function in tinfo/comp_hash.c (bsc#1154036). - CVE-2019-17595: Fixed a heap-based buffer over-read in fmt_entry function in tinfo/comp_hash.c (bsc#1154037). Bug fixes: - Fixed ppc64le build configuration (bsc#1134550). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 12-SP5: zypper in -t patch SUSE-SLE-SDK-12-SP5-2019-3094=1

References

#1131830 #1134550 #1154036 #1154037

Cross- CVE-2018-10754 CVE-2019-17594 CVE-2019-17595

Affected Products:

SUSE Linux Enterprise Software Development Kit 12-SP5

SUSE Linux Enterprise Software Development Kit 12-SP4

SUSE Linux Enterprise Server 12-SP5

SUSE Linux Enterprise Server 12-SP4

SUSE Linux Enterprise Desktop 12-SP4

SUSE CaaS Platform 3.0

https://www.suse.com/security/cve/CVE-2018-10754.html

https://www.suse.com/security/cve/CVE-2019-17594.html

https://www.suse.com/security/cve/CVE-2019-17595.html

https://bugzilla.suse.com/1131830

https://bugzilla.suse.com/1134550

https://bugzilla.suse.com/1154036

https://bugzilla.suse.com/1154037

Announcement ID: SUSE-SU-2019:3094-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here