Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

SUSE: 2022:3191-1 Moderate: libEMF Integer Overflow DoS

suse
Calendar Grey September 8, 2022
Dist Suse Esm H88
A new patch addressing an integer overflow in libEMF has been released for SUSE Linux systems. Please check for comprehensive information regarding the security update.
An update that fixes one vulnerability is now available

Summary

This update for libEMF fixes the following issues: - CVE-2020-13999: Fixed an integer overflow that could lead to denial of service via a crafted file (bsc#1173070). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.3: zypper in -t patch openSUSE-SLE-15.3-2022-3191=1 - SUSE Linux Enterprise Workstation Extension 15-SP3: zypper in -t patch SUSE-SLE-Product-WE-15-SP3-2022-3191=1 Package List: - openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64): libEMF-debuginfo-1.0.7-150000.3.6.1 libEMF-debugsource-1.0.7-150000.3.6.1 libEMF-devel-1.0.7-150000.3.6.1 libEMF-utils-1.0.7-150000.3.6.1

References

#1173070

Cross- CVE-2020-13999

CVSS scores:

CVE-2020-13999 (NVD) : 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

CVE-2020-13999 (SUSE): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Affected Products:

SUSE Linux Enterprise Desktop 15-SP3

SUSE Linux Enterprise Server 15-SP3

SUSE Linux Enterprise Server for SAP Applications 15-SP3

SUSE Linux Enterprise Workstation Extension 15-SP3

openSUSE Leap 15.3

https://www.suse.com/security/cve/CVE-2020-13999.html

https://bugzilla.suse.com/1173070

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2022:3191-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here