Several security issues were fixed in DOSBox.. ========================================================================= Ubuntu Security Notice USN-5356-1 March 30, 2022 dosbox vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 18.04 LTS Summary: Several security issues were fixed in DOSBox. Software Description: - dosbox: An Open Source DOS emulator to run old DOS games. Details: Alexandre Bartel discovered that DOSBox incorrectly handled long lines in certain files. An attacker could possibly use this issue to execute arbitrary code. (CVE-2019-7165) Alexandre Bartel discovered that DOSBox incorrectly performed access control over certain directories. An attacker could possibly use this issue to execute arbitrary code. (CVE-2019-12594) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 18.04 LTS: dosbox 0.74-4.3ubuntu0.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-5356-1 CVE-2019-12594, CVE-2019-7165 Package Information: https://launchpad.net/ubuntu/+source/dosbox/0.74-4.3ubuntu0.1 . Ubuntu Security Notice USN-5356-1 pertains to vulnerabilities identified in DOSBox impacting Ubuntu 18.04 LTS.. DOS Emulator, Security Flaws, Ubuntu Updates. . Severity: Critical. LinuxSecurity.com Team
An update that fixes two vulnerabilities is now available.. openSUSE Security Update: Security update for dosbox ______________________________________________________________________________ Announcement ID: openSUSE-SU-2019:1920-1 Rating: important References: #1140254 Cross-References: CVE-2019-12594 CVE-2019-7165 Affected Products: openSUSE Backports SLE-15-SP1 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update for dosbox fixes the following issues: Security issues fixed: - CVE-2019-7165: Fixed that a very long line inside a bat file would overflow the parsing buffer (bnc#1140254). - CVE-2019-12594: Added a basic permission system so that a program running inside DOSBox can't access the contents of /proc (e.g. /proc/self/mem) when / or /proc were (to be) mounted (bnc#1140254). - Several other fixes for out of bounds access and buffer overflows. This update was imported from the openSUSE:Leap:15.0:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP1: zypper in -t patch openSUSE-2019-1920=1 Package List: - openSUSE Backports SLE-15-SP1 (aarch64 ppc64le s390x x86_64): dosbox-0.74.3-bp151.4.3.1 References: https://www.suse.com/security/cve/CVE-2019-12594.html https://www.suse.com/security/cve/CVE-2019-7165.html https://bugzilla.suse.com/1140254 -- . Important openSUSE Security Patch addresses dosbox concerns regarding access rights and buffer overflow flaws.. openSUSE dosbox updates security patch. . Severity: Important. LinuxSecurity.com Team
An update that fixes two vulnerabilities is now available.. openSUSE Security Update: Security update for dosbox ______________________________________________________________________________ Announcement ID: openSUSE-SU-2019:1905-1 Rating: important References: #1140254 Cross-References: CVE-2019-12594 CVE-2019-7165 Affected Products: openSUSE Leap 15.1 openSUSE Leap 15.0 openSUSE Backports SLE-15 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update for dosbox fixes the following issues: Security issues fixed: - CVE-2019-7165: Fixed that a very long line inside a bat file would overflow the parsing buffer (bnc#1140254). - CVE-2019-12594: Added a basic permission system so that a program running inside DOSBox can't access the contents of /proc (e.g. /proc/self/mem) when / or /proc were (to be) mounted (bnc#1140254). - Several other fixes for out of bounds access and buffer overflows. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.1: zypper in -t patch openSUSE-2019-1905=1 - openSUSE Leap 15.0: zypper in -t patch openSUSE-2019-1905=1 - openSUSE Backports SLE-15: zypper in -t patch openSUSE-2019-1905=1 Package List: - openSUSE Leap 15.1 (x86_64): dosbox-0.74.3-lp151.3.3.1 dosbox-debuginfo-0.74.3-lp151.3.3.1 dosbox-debugsource-0.74.3-lp151.3.3.1 - openSUSE Leap 15.0 (x86_64): dosbox-0.74.3-lp150.2.3.1 dosbox-debuginfo-0.74.3-lp150.2.3.1 dosbox-debugsource-0.74.3-lp150.2.3.1 - openSUSE Backports SLE-15 (aarch64 ppc64le s390x x86_64): dosbox-0.74.3-bp150.3.3.1 References: https://www.suse.com/security/cve/CVE-2019-12594.html https://www.suse.com/security/cve/CVE-2019-7165.html https://bugzilla.suse.com/1140254 -- . A recent patch for dosbox addresses severe vulnerabilities in openSUSE systems, particularly concerning denial of service risks.. openSUSE Security Update, dosbox vulnerabilities, DOSBox fixes, openSUSE patch. . Severity: Important. LinuxSecurity.com Team
Two vulnerabilities were discovered in the DOSBox emulator, which could result in the execution of arbitrary code on the host running DOSBox when running a malicious executable in the emulator. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4478-1
Dosbox 0.74-3 is a security release: * Fixed that a very long line inside a bat file would overflow the parsing buffer. (CVE-2019-7165 by Alexandre Bartel) * Added a basic permission system so that a program running inside DOSBox can't access the contents of /proc (e.g. /proc/self/mem) when . MGASA-2019-0205 - Updated dosbox package fixes security vulnerabilities Publication date: 10 Jul 2019 URL: https://advisories.mageia.org/MGASA-2019-0205.html Type: security Affected Mageia releases: 6, 7 CVE: CVE-2019-7165, CVE-2019-12594 Dosbox 0.74-3 is a security release: * Fixed that a very long line inside a bat file would overflow the parsing buffer. (CVE-2019-7165 by Alexandre Bartel) * Added a basic permission system so that a program running inside DOSBox can't access the contents of /proc (e.g. /proc/self/mem) when / or /proc were (to be) mounted. (CVE-2019-12594 by Alexandre Bartel) It also brings several other fixes for out of bounds access and buffer overflows, and some fixes to the OpenGL rendering. The game compatibility should be identical to 0.74 and 0.74-2. It is recommended to use config -securemode when dealing with untrusted files. References: - https://bugs.mageia.org/show_bug.cgi?id=25013 - https://www.cve.org/CVERecord?id=CVE-2019-7165 - https://www.cve.org/CVERecord?id=CVE-2019-12594 SRPMS: - 7/core/dosbox-0.74.3-1.mga7 - 6/core/dosbox-0.74.3-1.mga6 . MGASA-2023-0210 Highlights essential qemu enhancements for security vulnerabilities and supplementary upgrades, dated 18 Oct 2023.. dosbox security update, Mageia advisory, buffer overflow fix. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.