Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
* bsc#1129596 Cross-References: * CVE-2019-9656 . # Security update for libofx Announcement ID: SUSE-SU-2024:3007-1 Rating: moderate References: * bsc#1129596 Cross-References: * CVE-2019-9656 CVSS scores: * CVE-2019-9656 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2019-9656 ( SUSE ): 5.3 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2019-9656 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2019-9656 ( NVD ): 8.8 CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 * SUSE Linux Enterprise Software Development Kit 12 SP5 * SUSE Linux Enterprise Workstation Extension 12 12-SP5 An update that solves one vulnerability can now be installed. ## Description: This update for libofx fixes the following issues: * CVE-2019-9656: Fixed null pointer dereference in function OFXApplication:startElement in lib/ofx_sgml.cpp (bsc#1129596) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Software Development Kit 12 SP5 zypper in -t patch SUSE-SLE-SDK-12-SP5-2024-3007=1 * SUSE Linux Enterprise Workstation Extension 12 12-SP5 zypper in -t patch SUSE-SLE-WE-12-SP5-2024-3007=1 ## Package List: * SUSE Linux Enterprise Software Development Kit 12 SP5 (aarch64 ppc64le s390x x86_64) * libofx-debuginfo-0.9.9-3.10.1 * libofx-debugsource-0.9.9-3.10.1 * libofx-devel-0.9.9-3.10.1 * libofx-0.9.9-3.10.1 * SUSE Linux Enterprise Workstation Extension 12 12-SP5 (x86_64) * libofx-debuginfo-0.9.9-3.10.1 * libofx-debugsource-0.9.9-3.10.1 * libofx6-debuginfo-0.9.9-3.10.1 * libofx-0.9.9-3.10.1 * libofx6-0.9.9-3.10.1 ## References: *https://www.suse.com/security/cve/CVE-2019-9656.html * https://bugzilla.suse.com/show_bug.cgi?id=1129596 . A recent patch for libofx resolves a critical null pointer vulnerability, enhancing overall reliability throughout various SUSE systems.. libofx, SUSE Security, software update, system reliability, SUSE Linux. . LinuxSecurity.com Team
The updated packages fix memory issues in libofx. (rhbz#2127755) References: - https://bugs.mageia.org/show_bug.cgi?id=30900 - https://bugzilla.redhat.com/show_bug.cgi?id=2127755 . MGASA-2022-0368 - Updated libofx packages fix security vulnerability Publication date: 13 Oct 2022 URL: https://advisories.mageia.org/MGASA-2022-0368.html Type: security Affected Mageia releases: 8 The updated packages fix memory issues in libofx. (rhbz#2127755) References: - https://bugs.mageia.org/show_bug.cgi?id=30900 - https://bugzilla.redhat.com/show_bug.cgi?id=2127755 - https://lists.fedoraproject.org/archives/list/
Memory-related security fixes, BZ 2127755. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-c9028047bf 2022-09-29 02:20:21.539366 --------------------------------------------------------------------------------Name : libofx Product : Fedora 35 Version : 0.10.7 Release : 2.fc35 URL : https://github.com/libofx/libofx Summary : A library for supporting Open Financial Exchange (OFX) Description : This is the LibOFX library. It is a API designed to allow applications to very easily support OFX command responses, usually provided by financial institutions. See for details and specification. --------------------------------------------------------------------------------Update Information: Memory-related security fixes, BZ 2127755 --------------------------------------------------------------------------------ChangeLog: * Mon Sep 19 2022 Gwyn Ciesla - 0.10.8-1 - Patches from BZ 2127755. * Fri Sep 9 2022 Gwyn Ciesla - 0.10.7-1 - 0.10.7 --------------------------------------------------------------------------------References: [ 1 ] Bug #2130202 - libofx: memory issues in libofx [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2130202 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-c9028047bf' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Memory-related security fixes, BZ 2127755. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-95000d85e2 2022-09-28 12:10:21.036669 --------------------------------------------------------------------------------Name : libofx Product : Fedora 36 Version : 0.10.7 Release : 2.fc36 URL : https://github.com/libofx/libofx Summary : A library for supporting Open Financial Exchange (OFX) Description : This is the LibOFX library. It is a API designed to allow applications to very easily support OFX command responses, usually provided by financial institutions. See for details and specification. --------------------------------------------------------------------------------Update Information: Memory-related security fixes, BZ 2127755 --------------------------------------------------------------------------------ChangeLog: * Mon Sep 19 2022 Gwyn Ciesla - 0.10.8-1 - Patches from BZ 2127755. --------------------------------------------------------------------------------References: [ 1 ] Bug #2130202 - libofx: memory issues in libofx [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2130202 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-95000d85e2' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Memory-related security fixes, BZ 2127755. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-cfb44eb79a 2022-09-24 00:15:02.320539 --------------------------------------------------------------------------------Name : libofx Product : Fedora 37 Version : 0.10.7 Release : 2.fc37 URL : https://github.com/libofx/libofx Summary : A library for supporting Open Financial Exchange (OFX) Description : This is the LibOFX library. It is a API designed to allow applications to very easily support OFX command responses, usually provided by financial institutions. See for details and specification. --------------------------------------------------------------------------------Update Information: Memory-related security fixes, BZ 2127755 --------------------------------------------------------------------------------ChangeLog: * Mon Sep 19 2022 Gwyn Ciesla - 0.10.8-1 - Patches from BZ 2127755. --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-cfb44eb79a' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
LibOFX could be made to crash.. =========================================================================Ubuntu Security Notice USN-4523-1 September 21, 2020 libofx vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.04 LTS Summary: LibOFX could be made to crash. Software Description: - libofx: client-side implementation of Open Financial Exchange specification Details: It was discovered that LibOFX did not properly check for errors in certain situations, leading to a NULL pointer dereference. A remote attacker could use this issue to cause a denial of service attack. (CVE-2019-9656) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 LTS: libofx-dev 1:0.9.10-1+deb8u2build0.16.04.1 libofx6 1:0.9.10-1+deb8u2build0.16.04.1 ofx 1:0.9.10-1+deb8u2build0.16.04.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-4523-1 CVE-2019-9656 Package Information: https://launchpad.net/ubuntu/+source/libofx/1:0.9.10-1+deb8u2build0.16.04.1 . Ubuntu Security Notice USN-4523-2 informs about a vulnerability in libofx that could lead to a denial of service stemming from a NULL pointer dereferencing issue.. libofx, denial of service, Ubuntu security, remote exploit, vulnerability management. . Severity: Critical. LinuxSecurity.com Team
Updated libofx packages fix security vulnerability: There is a NULL pointer dereference in the function OFXApplication::startElement in the file lib/ofx_sgml.cpp, as demonstrated by ofxdump (CVE-2019-9656). . MGASA-2019-0409 - Updated libofx packages fix security vulnerability Publication date: 25 Dec 2019 URL: https://advisories.mageia.org/MGASA-2019-0409.html Type: security Affected Mageia releases: 7 CVE: CVE-2019-9656 Updated libofx packages fix security vulnerability: There is a NULL pointer dereference in the function OFXApplication::startElement in the file lib/ofx_sgml.cpp, as demonstrated by ofxdump (CVE-2019-9656). References: - https://bugs.mageia.org/show_bug.cgi?id=25732 - https://lists.debian.org/debian-lts-announce/2019/11/msg00021.html - https://www.cve.org/CVERecord?id=CVE-2019-9656 SRPMS: - 7/core/libofx-0.9.15-1.mga7 . Recent libofx updates resolve NULL pointer vulnerabilities, strengthening security for Mageia 7 users. Ensure your system remains secure with this crucial patch.. Mageia Update, Libofx Patch, Security Maintenance, Software Vulnerability, Linux Advisory. . Severity: Critical. LinuxSecurity.com Team
There is a NULL pointer dereference in the function OFXApplication::startElement in the file lib/ofx_sgml.cpp, as demonstrated by ofxdump. . Package : libofx Version : 1:0.9.10-1+deb8u2 CVE ID : CVE-2019-9656 Debian Bug : #924350 There is a NULL pointer dereference in the function OFXApplication::startElement in the file lib/ofx_sgml.cpp, as demonstrated by ofxdump. For Debian 8 "Jessie", this problem has been fixed in version 1:0.9.10-1+deb8u2. We recommend that you upgrade your libofx packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Package : libofx Version : 1:0.9.10-1+deb8u2 CVE ID : CVE-2019-9656 Debian Bug : #924350 There is a . there, pointer, dereference, function, ofxapplication, startelement, lib/ofx. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.