Revision Date: | 2015-02-23 | Version: | 4 |
Title: | SUSE-SU-2014:1652-1 -- Security update for cpio (moderate) |
Description: | This cpio security update fixes the following buffer overflow issue andtwo non security issues:- fix an OOB write with cpio -i (bnc#907456) (CVE-2014-9112)- prevent cpio from extracting over a symlink (bnc#658010)- fix a truncation check in mt |
Family: | unix | Class: | patch |
Status: | ACCEPTED | Reference(s): | CVE-2014-9112 SUSE-SU-2014:1652-1
|
Platform(s): | SUSE Linux Enterprise Desktop 12 SUSE Linux Enterprise Server 12
| Product(s): | cpio
|
Definition Synopsis |
SUSE Linux Enterprise Server 12 and SUSE Linux Enterprise Desktop 12 release section Operation system section
SUSE Linux Enterprise Server 12 is installed
OR SUSE Linux Enterprise Desktop 12 is installed
AND cpio-lang is earlier than 0:2.11-29.1
SUSE Linux Enterprise Desktop 12 release section
SUSE Linux Enterprise Desktop 12 is installed
AND Packages match section
cpio is earlier than 0:2.11-29.1
OR cpio-debuginfo is earlier than 0:2.11-29.1
OR cpio-debugsource is earlier than 0:2.11-29.1
|