Oval Definition:oval:org.opensuse.security:def:20213624
Revision Date:2022-09-01Version:1
Title:CVE-2021-3624
Description:

There is an integer overflow vulnerability in dcraw. When the victim runs dcraw with a maliciously crafted X3F input image, arbitrary code may be executed in the victim's system.
Family:unixClass:vulnerability
Status:Reference(s):Mitre CVE-2021-3624
SUSE CVE-2021-3624
SUSE-SU-2022:1277-1
SUSE-SU-2022:1749-1
Platform(s):openSUSE Leap 15.3
openSUSE Tumbleweed
SUSE Linux Enterprise Desktop 12 SP5
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server for SAP Applications 12 SP5
SUSE Linux Enterprise Software Development Kit 12 SP5
SUSE Linux Enterprise Workstation Extension 12 SP5
Product(s):
Definition Synopsis
  • openSUSE Leap 15.3 is installed
  • AND Package Information
  • dcraw-9.28.0-150000.3.3.1 is installed
  • AND dcraw is signed with openSUSE key
  • OR
  • dcraw-lang-9.28.0-150000.3.3.1 is installed
  • AND dcraw-lang is signed with openSUSE key
  • Definition Synopsis
  • openSUSE Tumbleweed is installed
  • AND Package Information
  • dcraw-9.28.0-2.1 is installed
  • OR dcraw-lang-9.28.0-2.1 is installed
  • Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise Server 12 SP5 is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 12 SP5 is installed
  • OR SUSE Linux Enterprise Software Development Kit 12 SP5 is installed
  • AND dcraw-9.28.0-3.3.1 is installed
  • OR Package Information
  • SUSE Linux Enterprise Desktop 12 SP5 is installed
  • OR SUSE Linux Enterprise Server 12 SP5 is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 12 SP5 is installed
  • OR SUSE Linux Enterprise Workstation Extension 12 SP5 is installed
  • AND
  • dcraw-9.28.0-3.3.1 is installed
  • OR dcraw-lang-9.28.0-3.3.1 is installed
  • BACK