Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

SUSE: 2019:0005-1 Moderate Security Update for libraw DoS Issue

suse
Calendar Grey January 2, 2019
Dist Suse Esm H88
SUSE Security Patch resolves vulnerabilities in libraw to enhance protection proactively.
An update that fixes four vulnerabilities is now available

Summary

This update for libraw fixes the following issues: Security issues fixed: The following security vulnerabilities were addressed: - CVE-2018-5813: Fixed an error within the "parse_minolta()" function (dcraw/dcraw.c) that could be exploited to trigger an infinite loop via a specially crafted file. This could be exploited to cause a DoS.(boo#1103200). - CVE-2018-5815: Fixed an integer overflow in the internal/dcraw_common.cpp:parse_qt() function, that could be exploited to cause an infinite loop via a specially crafted Apple QuickTime file. (boo#1103206) - CVE-2018-5804,CVE-2018-5816: Fixed a type confusion error in the identify function (bsc#1097975) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".

References

#1097975 #1103200 #1103206

Cross- CVE-2018-5804 CVE-2018-5813 CVE-2018-5815

CVE-2018-5816

Affected Products:

SUSE Linux Enterprise Workstation Extension 15

SUSE Linux Enterprise Module for Open Buildservice Development Tools 15

https://www.suse.com/security/cve/CVE-2018-5804.html

https://www.suse.com/security/cve/CVE-2018-5813.html

https://www.suse.com/security/cve/CVE-2018-5815.html

https://www.suse.com/security/cve/CVE-2018-5816.html

https://bugzilla.suse.com/1097975

https://bugzilla.suse.com/1103200

https://bugzilla.suse.com/1103206

Announcement ID: SUSE-SU-2019:0005-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here