Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

SUSE: 2020:14388-1 Moderate: Gnuplot Buffer Overflow Fixes

suse
Calendar Grey June 8, 2020
Dist Suse Esm H88
Patch release for gnuplot addressing various security flaws in SUSE environments rated as intermediate severity.
An update that solves four vulnerabilities and has one errata is now available

Summary

This update for gnuplot fixes the following issues: Security issues fixed: - CVE-2018-19492: Fixed a buffer overflow in cairotrm_options function (bsc#1117463) - CVE-2018-19491: Fixed a buffer overflow in the PS_options function (bsc#1117464) - CVE-2018-19490: Fixed a heap-based buffer overflow in the df_generate_ascii_array_entry function (bsc#1117465) - CVE-2017-9670: Fixed a uninitialized stack variable vulnerability which could lead to a Denial of Service (bsc#1044638) Non-security issues fixed: - postscript output does not show any German "umlauts" (bsc#375175) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product:

References

#1044638 #1117463 #1117464 #1117465 #375175

Cross- CVE-2017-9670 CVE-2018-19490 CVE-2018-19491

CVE-2018-19492

Affected Products:

SUSE Linux Enterprise Debuginfo 11-SP4

https://www.suse.com/security/cve/CVE-2017-9670.html

https://www.suse.com/security/cve/CVE-2018-19490.html

https://www.suse.com/security/cve/CVE-2018-19491.html

https://www.suse.com/security/cve/CVE-2018-19492.html

https://bugzilla.suse.com/1044638

https://bugzilla.suse.com/1117463

https://bugzilla.suse.com/1117464

https://bugzilla.suse.com/1117465

https://bugzilla.suse.com/375175

Announcement ID: SUSE-SU-2020:14388-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here