Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

SUSE: 2020:2806-1 Addressing Moderate tar DoS Vulnerabilities Resolved

suse
Calendar Grey September 30, 2020
Dist Suse Esm H88
SUSE Security Patch for gzip addresses two denial of service vulnerabilities with moderate risk. Review the patch specifics here.
An update that fixes two vulnerabilities is now available

Summary

This update for tar fixes the following issues: Security issues fixed: - CVE-2019-9923: Fixed a denial of service while parsing certain archives with malformed extended headers in pax_decode_header() (bsc#1130496). - CVE-2018-20482: Fixed a denial of service when the '--sparse' option mishandles file shrinkage during read access (bsc#1120610). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server 12-SP5: zypper in -t patch SUSE-SLE-SERVER-12-SP5-2020-2806=1 Package List: - SUSE Linux Enterprise Server 12-SP5 (aarch64 ppc64le s390x x86_64): tar-1.27.1-15.6.3 tar-debuginfo-1.27.1-15.6.3

References

#1120610 #1130496

Cross- CVE-2018-20482 CVE-2019-9923

Affected Products:

SUSE Linux Enterprise Server 12-SP5

https://www.suse.com/security/cve/CVE-2018-20482.html

https://www.suse.com/security/cve/CVE-2019-9923.html

https://bugzilla.suse.com/1120610

https://bugzilla.suse.com/1130496

Announcement ID: SUSE-SU-2020:2806-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here