Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

SUSE Linux Enterprise 12-SP4: 2019:0127-1 Moderate: Libraw Buffer Overflow

suse
Calendar Grey January 18, 2019
Dist Suse Esm H88
This patch addresses various security vulnerabilities in libraw for OpenSUSE. Severity: medium, with 6 flaws rectified.
An update that fixes 6 vulnerabilities is now available

Summary

This update for libraw fixes the following issues: Security issues fixed: - CVE-2018-20365: Fixed a heap-based buffer overflow in the raw2image function of libraw_cxx.cpp (bsc#1120500) - CVE-2018-20364: Fixed a NULL pointer dereference in the copy_bayer function of libraw_cxx.cpp (bsc#1120499) - CVE-2018-20363: Fixed a NULL pointer dereference in the raw2image function of libraw_cxx.cpp (bsc#1120498) - CVE-2018-5817: Fixed an infinite loop in the unpacked_load_raw function of dcraw_common.cpp (bsc#1120515) - CVE-2018-5818: Fixed an infinite loop in the parse_rollei function of dcraw_common.cpp (bsc#1120516) - CVE-2018-5819: Fixed a denial of service in the parse_sinar_ia function of dcraw_common.cpp (bsc#1120517) Patch Instructions:

References

#1120498 #1120499 #1120500 #1120515 #1120516

#1120517

Cross- CVE-2018-20363 CVE-2018-20364 CVE-2018-20365

CVE-2018-5817 CVE-2018-5818 CVE-2018-5819

Affected Products:

SUSE Linux Enterprise Workstation Extension 12-SP4

SUSE Linux Enterprise Workstation Extension 12-SP3

SUSE Linux Enterprise Software Development Kit 12-SP4

SUSE Linux Enterprise Software Development Kit 12-SP3

SUSE Linux Enterprise Desktop 12-SP4

SUSE Linux Enterprise Desktop 12-SP3

https://www.suse.com/security/cve/CVE-2018-20363.html

https://www.suse.com/security/cve/CVE-2018-20364.html

https://www.suse.com/security/cve/CVE-2018-20365.html

https://www.suse.com/security/cve/CVE-2018-5817.html

https://www.suse.com/security/cve/CVE-2018-5818.html

Announcement ID: SUSE-SU-2019:0127-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here