An update that fixes three vulnerabilities is now available. . SUSE Security Update: Security update for libraw ______________________________________________________________________________ Announcement ID: SUSE-SU-2019:0002-1 Rating: moderate References: #1097973 #1097974 #1118894 Cross-References: CVE-2018-5805 CVE-2018-5806 CVE-2018-5808 Affected Products: SUSE Linux Enterprise Workstation Extension 12-SP4 SUSE Linux Enterprise Workstation Extension 12-SP3 SUSE Linux Enterprise Software Development Kit 12-SP4 SUSE Linux Enterprise Software Development Kit 12-SP3 SUSE Linux Enterprise Desktop 12-SP4 SUSE Linux Enterprise Desktop 12-SP3 ______________________________________________________________________________ An update that fixes three vulnerabilities is now available. Description: This update for libraw fixes the following issues: Security issues fixed: - CVE-2018-5808: Fixed a stack-based buffer overflow and code execution vulnerability in find_green() function internal/dcraw_common.cpp (bsc#1118894). - CVE-2018-5805: Fixed a boundary error within the quicktake_100_load_raw function (bsc#1097973) - CVE-2018-5806: Fixed a a NULL pointer dereference in the leaf_hdr_load_raw function (bsc#1097974) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Workstation Extension 12-SP4: zypper in -t patch SUSE-SLE-WE-12-SP4-2019-2=1 - SUSE Linux Enterprise Workstation Extension 12-SP3: zypper in -t patch SUSE-SLE-WE-12-SP3-2019-2=1 - SUSE Linux Enterprise Software Development Kit 12-SP4: zypper in -t patch SUSE-SLE-SDK-12-SP4-2019-2=1 - SUSE Linux Enterprise SoftwareDevelopment Kit 12-SP3: zypper in -t patch SUSE-SLE-SDK-12-SP3-2019-2=1 - SUSE Linux Enterprise Desktop 12-SP4: zypper in -t patch SUSE-SLE-DESKTOP-12-SP4-2019-2=1 - SUSE Linux Enterprise Desktop 12-SP3: zypper in -t patch SUSE-SLE-DESKTOP-12-SP3-2019-2=1 Package List: - SUSE Linux Enterprise Workstation Extension 12-SP4 (x86_64): libraw-debugsource-0.15.4-27.1 libraw9-0.15.4-27.1 libraw9-debuginfo-0.15.4-27.1 - SUSE Linux Enterprise Workstation Extension 12-SP3 (x86_64): libraw-debugsource-0.15.4-27.1 libraw9-0.15.4-27.1 libraw9-debuginfo-0.15.4-27.1 - SUSE Linux Enterprise Software Development Kit 12-SP4 (aarch64 ppc64le s390x x86_64): libraw-debugsource-0.15.4-27.1 libraw-devel-0.15.4-27.1 libraw-devel-static-0.15.4-27.1 libraw9-0.15.4-27.1 libraw9-debuginfo-0.15.4-27.1 - SUSE Linux Enterprise Software Development Kit 12-SP3 (aarch64 ppc64le s390x x86_64): libraw-debugsource-0.15.4-27.1 libraw-devel-0.15.4-27.1 libraw-devel-static-0.15.4-27.1 libraw9-0.15.4-27.1 libraw9-debuginfo-0.15.4-27.1 - SUSE Linux Enterprise Desktop 12-SP4 (x86_64): libraw-debugsource-0.15.4-27.1 libraw9-0.15.4-27.1 libraw9-debuginfo-0.15.4-27.1 - SUSE Linux Enterprise Desktop 12-SP3 (x86_64): libraw-debugsource-0.15.4-27.1 libraw9-0.15.4-27.1 libraw9-debuginfo-0.15.4-27.1 References: https://www.suse.com/security/cve/CVE-2018-5805.html https://www.suse.com/security/cve/CVE-2018-5806.html https://www.suse.com/security/cve/CVE-2018-5808.html https://bugzilla.suse.com/1097973 https://bugzilla.suse.com/1097974 https://bugzilla.suse.com/1118894 _______________________________________________ sle-security-updates mailing list
Important: gstreamer-plugins security update. Date: Thu, 8 Sep 2011 09:56:50 -0500 Reply-To: "Tyler L. Parsons" Sender: Security Errata for Scientific Linux From: "Tyler L. Parsons" Subject: Security ERRATA Important: gstreamer-plugins on SL4.x i386/x86_64 Comments: To: "
A boundary error in Audacity allows for the execution of arbitrary code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200903-03 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Audacity: User-assisted execution of arbitrary code Date: March 06, 2009 Bugs: #253493 ID: 200903-03 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= A boundary error in Audacity allows for the execution of arbitrary code. Background ========= Audacity is a free cross-platform audio editor. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 media-sound/audacity < 1.3.6 > = 1.3.6 Description ========== Houssamix discovered a boundary error in the String_parse::get_nonspace_quoted() function in lib-src/allegro/strparse.cpp. Impact ===== A remote attacker could entice a user into importing a specially crafted *.gro file, resulting in the execution of arbitrary code or a Denial of Service. Workaround ========= There is no known workaround at this time. Resolution ========= All Audacity users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =media-sound/audacity-1.3.6" References ========= [ 1 ] CVE-2009-0490 https://www.cve.org/CVERecord?id=CVE-2009-0490 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200903-03 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuringthe confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to
Get the latest Linux and open source security news straight to your inbox.