libESMTP through 1.0.6 mishandles domain copying into a fixed-size buffer in ntlm_build_type_2 in ntlm/ntlmstruct.c, as demonstrated by a stack-based buffer over-read. (CVE-2019-19977) References: . MGASA-2021-0503 - Updated libesmtp packages fix security vulnerability Publication date: 10 Nov 2021 URL: https://advisories.mageia.org/MGASA-2021-0503.html Type: security Affected Mageia releases: 8 CVE: CVE-2019-19977 libESMTP through 1.0.6 mishandles domain copying into a fixed-size buffer in ntlm_build_type_2 in ntlm/ntlmstruct.c, as demonstrated by a stack-based buffer over-read. (CVE-2019-19977) References: - https://bugs.mageia.org/show_bug.cgi?id=29416 - https://lists.suse.com/pipermail/sle-security-updates/2021-August/009358.html - - https://www.cve.org/CVERecord?id=CVE-2019-19977 SRPMS: - 8/core/libesmtp-1.0.6-12.1.mga8 . Mageia 2023-08-12 updates libssl to rectify a critical vulnerability, reinforcing overall system safety. Discover further details here.. libesmtp Update, Mageia Security, Buffer Over-Read Fix, Security Patch. . LinuxSecurity.com Team
An update that solves one vulnerability and has one errata is now available. . SUSE Security Update: Security update for libesmtp ______________________________________________________________________________ Announcement ID: SUSE-SU-2021:2937-2 Rating: important References: #1160462 #1189097 Cross-References: CVE-2019-19977 CVSS scores: CVE-2019-19977 (NVD) : 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVE-2019-19977 (SUSE): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:L Affected Products: SUSE MicroOS 5.1 ______________________________________________________________________________ An update that solves one vulnerability and has one errata is now available. Description: This update for libesmtp fixes the following issues: - CVE-2019-19977: Fixed stack-based buffer over-read in ntlm/ntlmstruct.c (bsc#1160462). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE MicroOS 5.1: zypper in -t patch SUSE-SUSE-MicroOS-5.1-2021-2937=1 Package List: - SUSE MicroOS 5.1 (aarch64 s390x x86_64): libesmtp-1.0.6-150.4.1 libesmtp-debuginfo-1.0.6-150.4.1 libesmtp-debugsource-1.0.6-150.4.1 References: https://www.suse.com/security/cve/CVE-2019-19977.html https://bugzilla.suse.com/1160462 https://bugzilla.suse.com/1189097 . SUSE Security Update for libcurl tackles critical vulnerabilities with essential fixes and detailed setup guidelines.. SUSE MicroOS Patch, libesmtp Security Update, Stack Overflow Fix, Software Update Instructions. . Severity: Important. LinuxSecurity.com Team
An update that solves one vulnerability and has one errata is now available. . openSUSE Security Update: Security update for libesmtp ______________________________________________________________________________ Announcement ID: openSUSE-SU-2021:1235-1 Rating: important References: #1160462 #1189097 Cross-References: CVE-2019-19977 CVSS scores: CVE-2019-19977 (NVD) : 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVE-2019-19977 (SUSE): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:L Affected Products: openSUSE Leap 15.2 ______________________________________________________________________________ An update that solves one vulnerability and has one errata is now available. Description: This update for libesmtp fixes the following issues: - CVE-2019-19977: Fixed stack-based buffer over-read in ntlm/ntlmstruct.c (bsc#1160462). This update was imported from the SUSE:SLE-15:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.2: zypper in -t patch openSUSE-2021-1235=1 Package List: - openSUSE Leap 15.2 (i586 x86_64): libesmtp-1.0.6-lp152.4.3.1 libesmtp-debuginfo-1.0.6-lp152.4.3.1 libesmtp-debugsource-1.0.6-lp152.4.3.1 libesmtp-devel-1.0.6-lp152.4.3.1 References: https://www.suse.com/security/cve/CVE-2019-19977.html https://bugzilla.suse.com/1160462 https://bugzilla.suse.com/1189097 . This patch resolves a significant vulnerability in libesmtp related to openSUSE Leap 15.2. Taking action is advised.. openSUSE Security, libesmtp Update, Important Software Update. . Severity: Important. LinuxSecurity.com Team
An update that solves one vulnerability and has one errata is now available. . openSUSE Security Update: Security update for libesmtp ______________________________________________________________________________ Announcement ID: openSUSE-SU-2021:2937-1 Rating: important References: #1160462 #1189097 Cross-References: CVE-2019-19977 CVSS scores: CVE-2019-19977 (NVD) : 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVE-2019-19977 (SUSE): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:L Affected Products: openSUSE Leap 15.3 ______________________________________________________________________________ An update that solves one vulnerability and has one errata is now available. Description: This update for libesmtp fixes the following issues: - CVE-2019-19977: Fixed stack-based buffer over-read in ntlm/ntlmstruct.c (bsc#1160462). Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.3: zypper in -t patch openSUSE-SLE-15.3-2021-2937=1 Package List: - openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64): libesmtp-1.0.6-150.4.1 libesmtp-debuginfo-1.0.6-150.4.1 libesmtp-debugsource-1.0.6-150.4.1 libesmtp-devel-1.0.6-150.4.1 References: https://www.suse.com/security/cve/CVE-2019-19977.html https://bugzilla.suse.com/1160462 https://bugzilla.suse.com/1189097 . A crucial patch is ready for libesmtp on openSUSE. It resolves a buffer over-read issue and mitigates potential vulnerabilities.. openSUSE libesmtp update buffer over-read patch. . Severity: Important. LinuxSecurity.com Team
An update that solves one vulnerability and has one errata is now available. . SUSE Security Update: Security update for libesmtp ______________________________________________________________________________ Announcement ID: SUSE-SU-2021:2937-1 Rating: important References: #1160462 #1189097 Cross-References: CVE-2019-19977 CVSS scores: CVE-2019-19977 (NVD) : 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVE-2019-19977 (SUSE): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:L Affected Products: SUSE MicroOS 5.0 SUSE Manager Server 4.0 SUSE Manager Retail Branch Server 4.0 SUSE Manager Proxy 4.0 SUSE Linux Enterprise Server for SAP 15-SP1 SUSE Linux Enterprise Server for SAP 15 SUSE Linux Enterprise Server 15-SP1-LTSS SUSE Linux Enterprise Server 15-SP1-BCL SUSE Linux Enterprise Server 15-LTSS SUSE Linux Enterprise Module for Basesystem 15-SP3 SUSE Linux Enterprise Module for Basesystem 15-SP2 SUSE Linux Enterprise High Performance Computing 15-SP1-LTSS SUSE Linux Enterprise High Performance Computing 15-SP1-ESPOS SUSE Linux Enterprise High Performance Computing 15-LTSS SUSE Linux Enterprise High Performance Computing 15-ESPOS SUSE Enterprise Storage 6 SUSE CaaS Platform 4.0 ______________________________________________________________________________ An update that solves one vulnerability and has one errata is now available. Description: This update for libesmtp fixes the following issues: - CVE-2019-19977: Fixed stack-based buffer over-read in ntlm/ntlmstruct.c (bsc#1160462). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installationmethods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE MicroOS 5.0: zypper in -t patch SUSE-SUSE-MicroOS-5.0-2021-2937=1 - SUSE Manager Server 4.0: zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Server-4.0-2021-2937=1 - SUSE Manager Retail Branch Server 4.0: zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Retail-Branch-Server-4.0-2021-2937=1 - SUSE Manager Proxy 4.0: zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Proxy-4.0-2021-2937=1 - SUSE Linux Enterprise Server for SAP 15-SP1: zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP1-2021-2937=1 - SUSE Linux Enterprise Server for SAP 15: zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-2021-2937=1 - SUSE Linux Enterprise Server 15-SP1-LTSS: zypper in -t patch SUSE-SLE-Product-SLES-15-SP1-LTSS-2021-2937=1 - SUSE Linux Enterprise Server 15-SP1-BCL: zypper in -t patch SUSE-SLE-Product-SLES-15-SP1-BCL-2021-2937=1 - SUSE Linux Enterprise Server 15-LTSS: zypper in -t patch SUSE-SLE-Product-SLES-15-2021-2937=1 - SUSE Linux Enterprise Module for Basesystem 15-SP3: zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP3-2021-2937=1 - SUSE Linux Enterprise Module for Basesystem 15-SP2: zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP2-2021-2937=1 - SUSE Linux Enterprise High Performance Computing 15-SP1-LTSS: zypper in -t patch SUSE-SLE-Product-HPC-15-SP1-LTSS-2021-2937=1 - SUSE Linux Enterprise High Performance Computing 15-SP1-ESPOS: zypper in -t patch SUSE-SLE-Product-HPC-15-SP1-ESPOS-2021-2937=1 - SUSE Linux Enterprise High Performance Computing 15-LTSS: zypper in -t patch SUSE-SLE-Product-HPC-15-2021-2937=1 - SUSE Linux Enterprise High Performance Computing 15-ESPOS: zypper in -t patch SUSE-SLE-Product-HPC-15-2021-2937=1 - SUSE Enterprise Storage 6: zypper in -t patch SUSE-Storage-6-2021-2937=1 - SUSE CaaS Platform4.0: To install this update, use the SUSE CaaS Platform 'skuba' tool. It will inform you if it detects new updates and let you then trigger updating of the complete cluster in a controlled way. Package List: - SUSE MicroOS 5.0 (aarch64 x86_64): libesmtp-1.0.6-150.4.1 libesmtp-debuginfo-1.0.6-150.4.1 libesmtp-debugsource-1.0.6-150.4.1 - SUSE Manager Server 4.0 (ppc64le s390x x86_64): libesmtp-1.0.6-150.4.1 libesmtp-debuginfo-1.0.6-150.4.1 libesmtp-debugsource-1.0.6-150.4.1 libesmtp-devel-1.0.6-150.4.1 - SUSE Manager Retail Branch Server 4.0 (x86_64): libesmtp-1.0.6-150.4.1 libesmtp-debuginfo-1.0.6-150.4.1 libesmtp-debugsource-1.0.6-150.4.1 libesmtp-devel-1.0.6-150.4.1 - SUSE Manager Proxy 4.0 (x86_64): libesmtp-1.0.6-150.4.1 libesmtp-debuginfo-1.0.6-150.4.1 libesmtp-debugsource-1.0.6-150.4.1 libesmtp-devel-1.0.6-150.4.1 - SUSE Linux Enterprise Server for SAP 15-SP1 (ppc64le x86_64): libesmtp-1.0.6-150.4.1 libesmtp-debuginfo-1.0.6-150.4.1 libesmtp-debugsource-1.0.6-150.4.1 libesmtp-devel-1.0.6-150.4.1 - SUSE Linux Enterprise Server for SAP 15 (ppc64le x86_64): libesmtp-1.0.6-150.4.1 libesmtp-debuginfo-1.0.6-150.4.1 libesmtp-debugsource-1.0.6-150.4.1 libesmtp-devel-1.0.6-150.4.1 - SUSE Linux Enterprise Server 15-SP1-LTSS (aarch64 ppc64le s390x x86_64): libesmtp-1.0.6-150.4.1 libesmtp-debuginfo-1.0.6-150.4.1 libesmtp-debugsource-1.0.6-150.4.1 libesmtp-devel-1.0.6-150.4.1 - SUSE Linux Enterprise Server 15-SP1-BCL (x86_64): libesmtp-1.0.6-150.4.1 libesmtp-debuginfo-1.0.6-150.4.1 libesmtp-debugsource-1.0.6-150.4.1 libesmtp-devel-1.0.6-150.4.1 - SUSE Linux Enterprise Server 15-LTSS (aarch64 s390x): libesmtp-1.0.6-150.4.1 libesmtp-debuginfo-1.0.6-150.4.1 libesmtp-debugsource-1.0.6-150.4.1 libesmtp-devel-1.0.6-150.4.1 - SUSE Linux EnterpriseModule for Basesystem 15-SP3 (aarch64 ppc64le s390x x86_64): libesmtp-1.0.6-150.4.1 libesmtp-debuginfo-1.0.6-150.4.1 libesmtp-debugsource-1.0.6-150.4.1 libesmtp-devel-1.0.6-150.4.1 - SUSE Linux Enterprise Module for Basesystem 15-SP2 (aarch64 ppc64le s390x x86_64): libesmtp-1.0.6-150.4.1 libesmtp-debuginfo-1.0.6-150.4.1 libesmtp-debugsource-1.0.6-150.4.1 libesmtp-devel-1.0.6-150.4.1 - SUSE Linux Enterprise High Performance Computing 15-SP1-LTSS (aarch64 x86_64): libesmtp-1.0.6-150.4.1 libesmtp-debuginfo-1.0.6-150.4.1 libesmtp-debugsource-1.0.6-150.4.1 libesmtp-devel-1.0.6-150.4.1 - SUSE Linux Enterprise High Performance Computing 15-SP1-ESPOS (aarch64 x86_64): libesmtp-1.0.6-150.4.1 libesmtp-debuginfo-1.0.6-150.4.1 libesmtp-debugsource-1.0.6-150.4.1 libesmtp-devel-1.0.6-150.4.1 - SUSE Linux Enterprise High Performance Computing 15-LTSS (aarch64 x86_64): libesmtp-1.0.6-150.4.1 libesmtp-debuginfo-1.0.6-150.4.1 libesmtp-debugsource-1.0.6-150.4.1 libesmtp-devel-1.0.6-150.4.1 - SUSE Linux Enterprise High Performance Computing 15-ESPOS (aarch64 x86_64): libesmtp-1.0.6-150.4.1 libesmtp-debuginfo-1.0.6-150.4.1 libesmtp-debugsource-1.0.6-150.4.1 libesmtp-devel-1.0.6-150.4.1 - SUSE Enterprise Storage 6 (aarch64 x86_64): libesmtp-1.0.6-150.4.1 libesmtp-debuginfo-1.0.6-150.4.1 libesmtp-debugsource-1.0.6-150.4.1 libesmtp-devel-1.0.6-150.4.1 - SUSE CaaS Platform 4.0 (x86_64): libesmtp-1.0.6-150.4.1 libesmtp-debuginfo-1.0.6-150.4.1 libesmtp-debugsource-1.0.6-150.4.1 libesmtp-devel-1.0.6-150.4.1 References: https://www.suse.com/security/cve/CVE-2019-19977.html https://bugzilla.suse.com/1160462 https://bugzilla.suse.com/1189097 . Essential enhancement for libesmtp addresses significant vulnerabilities. Safeguard your environments with the newest updates.. libesmtp Patch, security update,SUSE issues, buffer overflow fix. . Severity: Important. LinuxSecurity.com Team
An update that solves one vulnerability and has one errata is now available. . SUSE Security Update: Security update for libesmtp ______________________________________________________________________________ Announcement ID: SUSE-SU-2021:2917-1 Rating: important References: #1160462 #1189097 Cross-References: CVE-2019-19977 CVSS scores: CVE-2019-19977 (NVD) : 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVE-2019-19977 (SUSE): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:L Affected Products: SUSE OpenStack Cloud Crowbar 9 SUSE OpenStack Cloud Crowbar 8 SUSE OpenStack Cloud 9 SUSE OpenStack Cloud 8 SUSE Linux Enterprise Software Development Kit 12-SP5 SUSE Linux Enterprise Server for SAP 12-SP4 SUSE Linux Enterprise Server for SAP 12-SP3 SUSE Linux Enterprise Server 12-SP5 SUSE Linux Enterprise Server 12-SP4-LTSS SUSE Linux Enterprise Server 12-SP3-LTSS SUSE Linux Enterprise Server 12-SP3-BCL SUSE Linux Enterprise Server 12-SP2-BCL HPE Helion Openstack 8 ______________________________________________________________________________ An update that solves one vulnerability and has one errata is now available. Description: This update for libesmtp fixes the following issues: - CVE-2019-19977: Fix stack-based buffer over-read in ntlm/ntlmstruct.c (bsc#1160462). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE OpenStack Cloud Crowbar 9: zypper in -t patch SUSE-OpenStack-Cloud-Crowbar-9-2021-2917=1 - SUSE OpenStack Cloud Crowbar 8: zypper in -t patchSUSE-OpenStack-Cloud-Crowbar-8-2021-2917=1 - SUSE OpenStack Cloud 9: zypper in -t patch SUSE-OpenStack-Cloud-9-2021-2917=1 - SUSE OpenStack Cloud 8: zypper in -t patch SUSE-OpenStack-Cloud-8-2021-2917=1 - SUSE Linux Enterprise Software Development Kit 12-SP5: zypper in -t patch SUSE-SLE-SDK-12-SP5-2021-2917=1 - SUSE Linux Enterprise Server for SAP 12-SP4: zypper in -t patch SUSE-SLE-SAP-12-SP4-2021-2917=1 - SUSE Linux Enterprise Server for SAP 12-SP3: zypper in -t patch SUSE-SLE-SAP-12-SP3-2021-2917=1 - SUSE Linux Enterprise Server 12-SP5: zypper in -t patch SUSE-SLE-SERVER-12-SP5-2021-2917=1 - SUSE Linux Enterprise Server 12-SP4-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-SP4-LTSS-2021-2917=1 - SUSE Linux Enterprise Server 12-SP3-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-SP3-2021-2917=1 - SUSE Linux Enterprise Server 12-SP3-BCL: zypper in -t patch SUSE-SLE-SERVER-12-SP3-BCL-2021-2917=1 - SUSE Linux Enterprise Server 12-SP2-BCL: zypper in -t patch SUSE-SLE-SERVER-12-SP2-BCL-2021-2917=1 - HPE Helion Openstack 8: zypper in -t patch HPE-Helion-OpenStack-8-2021-2917=1 Package List: - SUSE OpenStack Cloud Crowbar 9 (x86_64): libesmtp-1.0.6-17.3.1 libesmtp-debuginfo-1.0.6-17.3.1 libesmtp-debugsource-1.0.6-17.3.1 - SUSE OpenStack Cloud Crowbar 8 (x86_64): libesmtp-1.0.6-17.3.1 libesmtp-debuginfo-1.0.6-17.3.1 libesmtp-debugsource-1.0.6-17.3.1 - SUSE OpenStack Cloud 9 (x86_64): libesmtp-1.0.6-17.3.1 libesmtp-debuginfo-1.0.6-17.3.1 libesmtp-debugsource-1.0.6-17.3.1 - SUSE OpenStack Cloud 8 (x86_64): libesmtp-1.0.6-17.3.1 libesmtp-debuginfo-1.0.6-17.3.1 libesmtp-debugsource-1.0.6-17.3.1 - SUSE Linux Enterprise Software Development Kit 12-SP5 (aarch64 ppc64le s390x x86_64): libesmtp-debuginfo-1.0.6-17.3.1 libesmtp-debugsource-1.0.6-17.3.1 libesmtp-devel-1.0.6-17.3.1 - SUSE LinuxEnterprise Server for SAP 12-SP4 (ppc64le x86_64): libesmtp-1.0.6-17.3.1 libesmtp-debuginfo-1.0.6-17.3.1 libesmtp-debugsource-1.0.6-17.3.1 - SUSE Linux Enterprise Server for SAP 12-SP3 (ppc64le x86_64): libesmtp-1.0.6-17.3.1 libesmtp-debuginfo-1.0.6-17.3.1 libesmtp-debugsource-1.0.6-17.3.1 - SUSE Linux Enterprise Server 12-SP5 (aarch64 ppc64le s390x x86_64): libesmtp-1.0.6-17.3.1 libesmtp-debuginfo-1.0.6-17.3.1 libesmtp-debugsource-1.0.6-17.3.1 - SUSE Linux Enterprise Server 12-SP4-LTSS (aarch64 ppc64le s390x x86_64): libesmtp-1.0.6-17.3.1 libesmtp-debuginfo-1.0.6-17.3.1 libesmtp-debugsource-1.0.6-17.3.1 - SUSE Linux Enterprise Server 12-SP3-LTSS (aarch64 ppc64le s390x x86_64): libesmtp-1.0.6-17.3.1 libesmtp-debuginfo-1.0.6-17.3.1 libesmtp-debugsource-1.0.6-17.3.1 - SUSE Linux Enterprise Server 12-SP3-BCL (x86_64): libesmtp-1.0.6-17.3.1 libesmtp-debuginfo-1.0.6-17.3.1 libesmtp-debugsource-1.0.6-17.3.1 - SUSE Linux Enterprise Server 12-SP2-BCL (x86_64): libesmtp-1.0.6-17.3.1 libesmtp-debuginfo-1.0.6-17.3.1 libesmtp-debugsource-1.0.6-17.3.1 - HPE Helion Openstack 8 (x86_64): libesmtp-1.0.6-17.3.1 libesmtp-debuginfo-1.0.6-17.3.1 libesmtp-debugsource-1.0.6-17.3.1 References: https://www.suse.com/security/cve/CVE-2019-19977.html https://bugzilla.suse.com/1160462 https://bugzilla.suse.com/1189097 . An important patch for libesmtp resolves a buffer overflow vulnerability according to SUSE security bulletin SUSE-SU-2021:2917-1.. libesmtp update,SUSE Security,buffer over-read fix,SUSE Linux patch. . Severity: Critical. LinuxSecurity.com Team
An update that solves one vulnerability and has one errata is now available. . SUSE Security Update: Security update for libesmtp ______________________________________________________________________________ Announcement ID: SUSE-SU-2021:14793-1 Rating: important References: #1160462 #1189097 Cross-References: CVE-2019-19977 CVSS scores: CVE-2019-19977 (NVD) : 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVE-2019-19977 (SUSE): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:L Affected Products: SUSE Linux Enterprise Server 11-SP4-LTSS SUSE Linux Enterprise Point of Sale 11-SP3 SUSE Linux Enterprise Debuginfo 11-SP4 SUSE Linux Enterprise Debuginfo 11-SP3 ______________________________________________________________________________ An update that solves one vulnerability and has one errata is now available. Description: This update for libesmtp fixes the following issues: - CVE-2019-19977: Fixed stack-based buffer over-read in ntlm/ntlmstruct.c (bsc#1160462). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server 11-SP4-LTSS: zypper in -t patch slessp4-libesmtp-14793=1 - SUSE Linux Enterprise Point of Sale 11-SP3: zypper in -t patch sleposp3-libesmtp-14793=1 - SUSE Linux Enterprise Debuginfo 11-SP4: zypper in -t patch dbgsp4-libesmtp-14793=1 - SUSE Linux Enterprise Debuginfo 11-SP3: zypper in -t patch dbgsp3-libesmtp-14793=1 Package List: - SUSE Linux Enterprise Server 11-SP4-LTSS (i586 ppc64 s390x x86_64): libesmtp-1.0.4-157.18.3.1 - SUSE Linux Enterprise Point of Sale 11-SP3 (i586): libesmtp-1.0.4-157.18.3.1 - SUSE Linux Enterprise Debuginfo 11-SP4 (i586 ppc64 s390xx86_64): libesmtp-debuginfo-1.0.4-157.18.3.1 libesmtp-debugsource-1.0.4-157.18.3.1 - SUSE Linux Enterprise Debuginfo 11-SP3 (i586 s390x x86_64): libesmtp-debuginfo-1.0.4-157.18.3.1 libesmtp-debugsource-1.0.4-157.18.3.1 References: https://www.suse.com/security/cve/CVE-2019-19977.html https://bugzilla.suse.com/1160462 https://bugzilla.suse.com/1189097 . Critical SUSE Security Patch for libesmtp resolves a buffer over-read vulnerability. Ensure safety by applying this update without delay.. Libesmtp Patch, SUSE Security Update, Buffer Over-read Fix. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.