This update fixes the following security vulnerabilities: CVE-2018-20536, CVE-2018-20537, CVE-2018-20539, CVE-2018-20540. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-b0695fcdf7 2020-04-25 02:59:31.862802 --------------------------------------------------------------------------------Name : liblas Product : Fedora 31 Version : 1.8.1 Release : 5.fc31 URL : Summary : Library for reading and writing the very common LAS LiDAR format Description : libLAS is a C/C++ library for reading and writing the very common LAS LiDAR format. The ASPRS LAS format is a sequential binary format used to store data from LiDAR sensors and by LiDAR processing software for data interchange and archival. --------------------------------------------------------------------------------Update Information: This update fixes the following security vulnerabilities: CVE-2018-20536, CVE-2018-20537, CVE-2018-20539, CVE-2018-20540 --------------------------------------------------------------------------------ChangeLog: * Tue Apr 14 2020 Sandro Mani - 1.8.1-5 - Add patches for CVE-2018-20539, CVE-2018-20537, CVE-2018-20536, CVE-2018-20540 * Tue Mar 3 2020 Sandro Mani - 1.8.1-4 - Rebuild (gdal) * Wed Jan 29 2020 Fedora Release Engineering - 1.8.1-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_32_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #1652609 - There is a Segmentation fault triggered by illegal address access at liblas::SpatialReference::GetGTIF()(src/spatialreference.cpp:515) in libLAS while will cause dos attack. https://bugzilla.redhat.com/show_bug.cgi?id=1652609 [ 2 ] Bug #1652610 - There is a heap-buffer-overflow at liblas::SpatialReference::GetGTIF()(src/spatialreference.cpp:518) in libLAS while will cause dos attack. https://bugzilla.redhat.com/show_bug.cgi?id=1652610 [ 3 ] Bug #1652611 -There is an illegal address access at liblas::SpatialReference::GetGTIF()(src/spatialreference.cpp:532) in libLAS while will cause dos attack. https://bugzilla.redhat.com/show_bug.cgi?id=1652611 [ 4 ] Bug #1652612 - There is memory leak at liblas::Open(liblas/liblas.hpp:127) in libLAS. https://bugzilla.redhat.com/show_bug.cgi?id=1652612 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-b0695fcdf7' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
libsolv: NULL pointer dereference in function testcase_read (CVE-2018-20532) * libsolv: NULL pointer dereference in function testcase_str2dep_complex (CVE-2018-20533) * libsolv: illegal address access in pool_whatprovides in src/pool.h (CVE-2018-20534) SL7 x86_64 libsolv-0.6.34-4.el7.x86_64.rpm libsolv-0.6.34-4.el7.i686.rpm libsolv-devel-0.6.34-4.el7.i686.rpm libsolv-tools [More...]. Synopsis: Low: libsolv security and bug fix update Advisory ID: SLSA-2019:2290-1 Issue Date: 2019-08-06 CVE Numbers: CVE-2018-20534 CVE-2018-20532 CVE-2018-20533 -- Security Fix(es): * libsolv: NULL pointer dereference in function testcase_read (CVE-2018-20532) * libsolv: NULL pointer dereference in function testcase_str2dep_complex (CVE-2018-20533) * libsolv: illegal address access in pool_whatprovides in src/pool.h (CVE-2018-20534) -- SL7 x86_64 libsolv-0.6.34-4.el7.x86_64.rpm libsolv-0.6.34-4.el7.i686.rpm libsolv-devel-0.6.34-4.el7.i686.rpm libsolv-tools-0.6.34-4.el7.x86_64.rpm libsolv-demo-0.6.34-4.el7.x86_64.rpm python2-solv-0.6.34-4.el7.x86_64.rpm libsolv-devel-0.6.34-4.el7.x86_64.rpm libsolv-tools-0.6.34-4.el7.i686.rpm libsolv-debuginfo-0.6.34-4.el7.i686.rpm libsolv-debuginfo-0.6.34-4.el7.x86_64.rpm - Scientific Linux Development Team . Minor critical libsolv security patch notice for SL7 tackling null reference concerns and improper memory access.. libsolv security, Scientific Linux advisory, NULL pointer fix. . Severity: Low. LinuxSecurity.com Team
An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for libwpd ______________________________________________________________________________ Announcement ID: SUSE-SU-2018:3812-2 Rating: important References: #1115713 Cross-References: CVE-2018-19208 Affected Products: SUSE Linux Enterprise Workstation Extension 12-SP4 SUSE Linux Enterprise Software Development Kit 12-SP4 SUSE Linux Enterprise Desktop 12-SP4 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for libwpd fixes the following issues: Security issue fixed: - CVE-2018-19208: Fixed illegal address access inside libwpd at function WP6ContentListener:defineTable (bsc#1115713). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Workstation Extension 12-SP4: zypper in -t patch SUSE-SLE-WE-12-SP4-2018-2706=1 - SUSE Linux Enterprise Software Development Kit 12-SP4: zypper in -t patch SUSE-SLE-SDK-12-SP4-2018-2706=1 - SUSE Linux Enterprise Desktop 12-SP4: zypper in -t patch SUSE-SLE-DESKTOP-12-SP4-2018-2706=1 Package List: - SUSE Linux Enterprise Workstation Extension 12-SP4 (x86_64): libwpd-0_10-10-0.10.2-2.7.1 libwpd-0_10-10-debuginfo-0.10.2-2.7.1 libwpd-debugsource-0.10.2-2.7.1 - SUSE Linux Enterprise Software Development Kit 12-SP4 (aarch64 ppc64le s390x x86_64): libwpd-0_10-10-0.10.2-2.7.1 libwpd-0_10-10-debuginfo-0.10.2-2.7.1 libwpd-debugsource-0.10.2-2.7.1 libwpd-devel-0.10.2-2.7.1 - SUSE Linux Enterprise Software Development Kit 12-SP4 (noarch): libwpd-devel-doc-0.10.2-2.7.1 - SUSE LinuxEnterprise Desktop 12-SP4 (x86_64): libwpd-0_10-10-0.10.2-2.7.1 libwpd-0_10-10-debuginfo-0.10.2-2.7.1 libwpd-debugsource-0.10.2-2.7.1 References: https://www.suse.com/security/cve/CVE-2018-19208.html https://bugzilla.suse.com/1115713 _______________________________________________ sle-security-updates mailing list
An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for libwpd ______________________________________________________________________________ Announcement ID: SUSE-SU-2018:3870-1 Rating: important References: #1115713 Cross-References: CVE-2018-19208 Affected Products: SUSE Linux Enterprise Workstation Extension 15 SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for libwpd fixes the following issues: Security issue fixed: - CVE-2018-19208: Fixed illegal address access inside libwpd at function WP6ContentListener:defineTable (bsc#1115713). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Workstation Extension 15: zypper in -t patch SUSE-SLE-Product-WE-15-2018-2761=1 - SUSE Linux Enterprise Module for Open Buildservice Development Tools 15: zypper in -t patch SUSE-SLE-Module-Development-Tools-OBS-15-2018-2761=1 Package List: - SUSE Linux Enterprise Workstation Extension 15 (x86_64): libwpd-0_10-10-0.10.2-3.3.1 libwpd-0_10-10-debuginfo-0.10.2-3.3.1 libwpd-debuginfo-0.10.2-3.3.1 libwpd-debugsource-0.10.2-3.3.1 libwpd-devel-0.10.2-3.3.1 - SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 (aarch64 ppc64le s390x x86_64): libwpd-debuginfo-0.10.2-3.3.1 libwpd-debugsource-0.10.2-3.3.1 libwpd-tools-0.10.2-3.3.1 libwpd-tools-debuginfo-0.10.2-3.3.1 - SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 (noarch): libwpd-devel-doc-0.10.2-3.3.1 References: https://www.suse.com/security/cve/CVE-2018-19208.html https://bugzilla.suse.com/1115713 _______________________________________________ sle-security-updates mailing list
An update that fixes one vulnerability is now available.. openSUSE Security Update: Security update for libwpd ______________________________________________________________________________ Announcement ID: openSUSE-SU-2018:3842-1 Rating: important References: #1115713 Cross-References: CVE-2018-19208 Affected Products: openSUSE Leap 42.3 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for libwpd fixes the following issues: Security issue fixed: - CVE-2018-19208: Fixed illegal address access inside libwpd at function WP6ContentListener:defineTable (bsc#1115713). This update was imported from the SUSE:SLE-12:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 42.3: zypper in -t patch openSUSE-2018-1440=1 Package List: - openSUSE Leap 42.3 (x86_64): libwpd-0_10-10-0.10.2-11.1 libwpd-0_10-10-debuginfo-0.10.2-11.1 libwpd-debugsource-0.10.2-11.1 libwpd-devel-0.10.2-11.1 libwpd-tools-0.10.2-11.1 libwpd-tools-debuginfo-0.10.2-11.1 - openSUSE Leap 42.3 (noarch): libwpd-devel-doc-0.10.2-11.1 References: https://www.suse.com/security/cve/CVE-2018-19208.html https://bugzilla.suse.com/1115713 -- . A crucial announcement for openSUSE Leap 42.3 tackles a vulnerability in libexiv2, bolstering the system's defenses.. openSUSE Leap Patch, libwpd Security Update, Important Linux Update. . Severity: Important. LinuxSecurity.com Team
An update that fixes 7 vulnerabilities is now available. An update that fixes 7 vulnerabilities is now available. An update that fixes 7 vulnerabilities is now available.. SUSE Security Update: Security update for ncurses ______________________________________________________________________________ Announcement ID: SUSE-SU-2017:3183-1 Rating: important References: #1056127 #1056128 #1056129 #1056131 #1056132 #1056136 #1069530 Cross-References: CVE-2017-13728 CVE-2017-13729 CVE-2017-13730 CVE-2017-13731 CVE-2017-13732 CVE-2017-13733 CVE-2017-16879 Affected Products: SUSE Linux Enterprise Software Development Kit 11-SP4 SUSE Linux Enterprise Server 11-SP4 SUSE Linux Enterprise Debuginfo 11-SP4 ______________________________________________________________________________ An update that fixes 7 vulnerabilities is now available. Description: This update for ncurses fixes the following issues: Security issues fixed: - CVE-2017-13728: Fix infinite loop in the next_char function in comp_scan.c (bsc#1056136). - CVE-2017-13729: Fix illegal address access in the _nc_save_str (bsc#1056132). - CVE-2017-13730: Fix illegal address access in the function _nc_read_entry_source() (bsc#1056131). - CVE-2017-13731: Fix illegal address access in the function postprocess_termcap() (bsc#1056129). - CVE-2017-13732: Fix illegal address access in the function dump_uses() (bsc#1056128). - CVE-2017-13733: Fix illegal address access in the fmt_entry function (bsc#1056127). - CVE-2017-16879: Fix stack-based buffer overflow in the _nc_write_entry() function (bsc#1069530). Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 11-SP4: zypper in -t patchsdksp4-ncurses-13364=1 - SUSE Linux Enterprise Server 11-SP4: zypper in -t patch slessp4-ncurses-13364=1 - SUSE Linux Enterprise Debuginfo 11-SP4: zypper in -t patch dbgsp4-ncurses-13364=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Software Development Kit 11-SP4 (i586 x86_64): ncurses-devel-5.6-93.12.1 tack-5.6-93.12.1 - SUSE Linux Enterprise Software Development Kit 11-SP4 (x86_64): ncurses-devel-32bit-5.6-93.12.1 - SUSE Linux Enterprise Server 11-SP4 (i586 ia64 ppc64 s390x x86_64): libncurses5-5.6-93.12.1 libncurses6-5.6-93.12.1 ncurses-devel-5.6-93.12.1 ncurses-utils-5.6-93.12.1 tack-5.6-93.12.1 terminfo-5.6-93.12.1 terminfo-base-5.6-93.12.1 - SUSE Linux Enterprise Server 11-SP4 (ppc64 s390x x86_64): libncurses5-32bit-5.6-93.12.1 libncurses6-32bit-5.6-93.12.1 ncurses-devel-32bit-5.6-93.12.1 - SUSE Linux Enterprise Server 11-SP4 (ia64): libncurses5-x86-5.6-93.12.1 libncurses6-x86-5.6-93.12.1 - SUSE Linux Enterprise Debuginfo 11-SP4 (i586 ia64 ppc64 s390x x86_64): ncurses-debuginfo-5.6-93.12.1 ncurses-debugsource-5.6-93.12.1 References: https://www.suse.com/security/cve/CVE-2017-13728.html https://www.suse.com/security/cve/CVE-2017-13729.html https://www.suse.com/security/cve/CVE-2017-13730.html https://www.suse.com/security/cve/CVE-2017-13731.html https://www.suse.com/security/cve/CVE-2017-13732.html https://www.suse.com/security/cve/CVE-2017-13733.html https://www.suse.com/security/cve/CVE-2017-16879.html https://bugzilla.suse.com/1056127 https://bugzilla.suse.com/1056128 https://bugzilla.suse.com/1056129 https://bugzilla.suse.com/1056131 https://bugzilla.suse.com/1056132 https://bugzilla.suse.com/1056136 https://bugzilla.suse.com/1069530 . SUSE Security Patch for openssl tackles urgent problems and supplies crucial solutions for software weaknesses.. SUSESecurity Update,ncurses Fixes,System Vulnerabilities. . Severity: Important. LinuxSecurity.com Team
Security fix for CVE-2017-13738 CVE-2017-13739 CVE-2017-13740 CVE-2017-13741 CVE-2017-13742 CVE-2017-13743 CVE-2017-13744. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-f9f6398158 2017-11-15 15:47:48.464137 --------------------------------------------------------------------------------Name : liblouis Product : Fedora 27 Version : 2.6.2 Release : 12.fc27 URL : Summary : Braille translation and back-translation library Description : Liblouis is an open-source braille translator and back-translator named in honor of Louis Braille. It features support for computer and literary braille, supports contracted and uncontracted translation for many languages and has support for hyphenation. New languages can easily be added through tables that support a rule- or dictionary based approach. Liblouis also supports math braille (Nemeth and Marburg). Liblouis has features to support screen-reading programs. This has led to its use in two open-source screen readers, NVDA and Orca. It is also used in some commercial assistive technology applications for example by ViewPlus. Liblouis is based on the translation routines in the BRLTTY screen reader for Linux. It has, however, gone far beyond these routines. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2017-13738 CVE-2017-13739 CVE-2017-13740 CVE-2017-13741 CVE-2017-13742 CVE-2017-13743 CVE-2017-13744 --------------------------------------------------------------------------------References: [ 1 ] Bug #1488942 - CVE-2017-13743 liblouis: Buffer overflow in the function _lou_showString() https://bugzilla.redhat.com/show_bug.cgi?id=1488942 [ 2 ] Bug #1488939 - CVE-2017-13742 liblouis: Stack-buffer overflow in the function includeFile() https://bugzilla.redhat.com/show_bug.cgi?id=1488939 [ 3 ] Bug #1488938 - CVE-2017-13741 liblouis: Use-after-freein the function compileBrailleIndicator() https://bugzilla.redhat.com/show_bug.cgi?id=1488938 [ 4 ] Bug #1488937 - CVE-2017-13740 liblouis: Stack-buffer overflow in the parseChars() function https://bugzilla.redhat.com/show_bug.cgi?id=1488937 [ 5 ] Bug #1488936 - CVE-2017-13739 liblouis: Heap-buffer overflow resulting in an out-of-bounds write in resolveSubtable() function https://bugzilla.redhat.com/show_bug.cgi?id=1488936 [ 6 ] Bug #1488935 - CVE-2017-13744 liblouis: Illegal address access in the _lou_getALine() function https://bugzilla.redhat.com/show_bug.cgi?id=1488935 [ 7 ] Bug #1488933 - CVE-2017-13738 liblouis: Illegal address access in the _lou_getALine function https://bugzilla.redhat.com/show_bug.cgi?id=1488933 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade liblouis' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.