Oval Definition:oval:org.opensuse.security:def:51067
Revision Date:2020-12-01Version:1
Title:Security update for cairo (Moderate)
Description:

This update for cairo fixes the following issues:

The following security vulnerability was addressed:

- CVE-2017-9814: Fixed and out-of-bounds read in cairo-truetype-subset.c by replacing the malloc implementation with _cairo_malloc and checking the size before memory allocation (bsc#1049092)
Family:unixClass:patch
Status:Reference(s):1012382
1043912
1044189
1046302
1046306
1046307
1046543
1049092
1050244
1051510
1054914
1055014
1055117
1058659
1060463
1064232
1065600
1065729
1068032
1069138
1071995
1077761
1077989
1078720
1080157
1082555
1083647
1083663
1084332
1085042
1085262
1086282
1089663
1090528
1092903
1093389
1094244
1095344
1096748
1097105
1098459
1098822
1099922
1099999
1100000
1100001
1100132
1101557
1101669
1102346
1102870
1102875
1102877
1102879
1102882
1102896
1103363
1103387
1103421
1103948
1103949
1103961
1104172
1104353
1104824
1105247
1105524
1105536
1105597
1105603
1105672
1105907
1106007
1106016
1106105
1106121
1106170
1106178
1106191
1106229
1106230
1106231
1106233
1106235
1106236
1106237
1106238
1106240
1106291
1106297
1106333
1106369
1106426
1106427
1106464
1106509
1106511
1106594
1106636
1106688
1106697
1106743
1106779
1106800
1106890
1106891
1106892
1106893
1106894
1106896
1106897
1106898
1106899
1106900
1106901
1106902
1106903
1106905
1106906
1106948
1106995
1107008
1107060
1107061
1107065
1107073
1107074
1107078
1107265
1107319
1107320
1107522
1107535
1107689
1107735
1107756
1107870
1107924
1107945
1107966
1108010
1108093
1108243
1108520
1108870
1109269
1109511
1112142
1112143
1112144
1112146
1112147
1112148
1112152
1112153
1126088
1130165
1132666
1136035
1137443
1140750
1143650
1148643
1151612
1156402
1158257
1159819
1163985
1169134
1169746
1170487
1171746
1171924
1171978
1172437
1174591
1174628
1175061
1175240
1175781
1177843
920344
CVE-2006-2607
CVE-2009-0163
CVE-2009-2820
CVE-2009-3553
CVE-2010-0393
CVE-2010-0424
CVE-2010-0540
CVE-2010-0542
CVE-2010-1748
CVE-2010-2941
CVE-2012-5519
CVE-2012-6094
CVE-2014-2856
CVE-2014-3537
CVE-2014-5029
CVE-2014-5030
CVE-2014-5031
CVE-2017-9814
CVE-2018-1000199
CVE-2018-10938
CVE-2018-10940
CVE-2018-1128
CVE-2018-1129
CVE-2018-12896
CVE-2018-13093
CVE-2018-13094
CVE-2018-13095
CVE-2018-13785
CVE-2018-14613
CVE-2018-14617
CVE-2018-16435
CVE-2018-16658
CVE-2018-3136
CVE-2018-3139
CVE-2018-3149
CVE-2018-3169
CVE-2018-3180
CVE-2018-3183
CVE-2018-3214
CVE-2018-6554
CVE-2018-6555
CVE-2019-12735
CVE-2019-13314
CVE-2019-14275
CVE-2019-17006
CVE-2019-2201
CVE-2019-2614
CVE-2019-2627
CVE-2019-2628
CVE-2019-9755
CVE-2020-10757
CVE-2020-12399
CVE-2020-14344
CVE-2020-1720
CVE-2020-25660
SUSE-SU-2018:1873-1
SUSE-SU-2018:2981-1
SUSE-SU-2019:0058-1
SUSE-SU-2019:1001-1
SUSE-SU-2019:1457-1
SUSE-SU-2019:2020-1
SUSE-SU-2019:2971-2
SUSE-SU-2020:1677-1
SUSE-SU-2020:2149-1
SUSE-SU-2020:2951-1
Platform(s):SUSE Linux Enterprise Desktop 11 SP2
SUSE Linux Enterprise Desktop 11 SP4
SUSE Linux Enterprise Desktop 12
SUSE Linux Enterprise Desktop 12 SP1
SUSE Linux Enterprise Desktop 12 SP2
SUSE Linux Enterprise Desktop 12 SP3
SUSE Linux Enterprise Desktop 12 SP4
SUSE Linux Enterprise Module for additional PackageHub packages 15 SP2
SUSE Linux Enterprise Module for Desktop Applications 15
SUSE Linux Enterprise Module for Legacy Software 15
SUSE Linux Enterprise Module for Live Patching 15
SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 SP2
SUSE Linux Enterprise Module for Server Applications 15
SUSE Linux Enterprise Module for Server Applications 15 SP1
SUSE Linux Enterprise Server 12 SP1
SUSE Linux Enterprise Server 12 SP1-LTSS
SUSE Linux Enterprise Server 12 SP2
SUSE Linux Enterprise Server 12 SP2-BCL
SUSE Linux Enterprise Server 12 SP2-ESPOS
SUSE Linux Enterprise Server 12 SP2-LTSS
SUSE Linux Enterprise Server 12 SP3
SUSE Linux Enterprise Server 12 SP3-ESPOS
SUSE Linux Enterprise Server 12 SP3-LTSS
SUSE Linux Enterprise Server 12 SP3-TERADATA
SUSE Linux Enterprise Server 12 SP4
SUSE Linux Enterprise Server 15-LTSS
SUSE Linux Enterprise Workstation Extension 15
SUSE Linux Enterprise Workstation Extension 15 SP2
SUSE OpenStack Cloud 6
SUSE OpenStack Cloud 7
SUSE OpenStack Cloud 8
SUSE OpenStack Cloud Crowbar 8
Product(s):
Definition Synopsis
  • SUSE Linux Enterprise Desktop 11 SP2 is installed
  • AND Package Information
  • libpython2_6-1_0-2.6.8-0.23 is installed
  • OR libpython2_6-1_0-32bit-2.6.8-0.23 is installed
  • OR python-2.6.8-0.23 is installed
  • OR python-base-2.6.8-0.23 is installed
  • OR python-base-32bit-2.6.8-0.23 is installed
  • OR python-curses-2.6.8-0.23 is installed
  • OR python-devel-2.6.8-0.23 is installed
  • OR python-tk-2.6.8-0.23 is installed
  • OR python-xml-2.6.8-0.23 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Desktop 11 SP4 is installed
  • AND Package Information
  • MozillaFirefox-31.8.0esr-0.10 is installed
  • OR MozillaFirefox-translations-31.8.0esr-0.10 is installed
  • OR libfreebl3-3.19.2_CKBI_1.98-0.10 is installed
  • OR libfreebl3-32bit-3.19.2_CKBI_1.98-0.10 is installed
  • OR libsoftokn3-3.19.2_CKBI_1.98-0.10 is installed
  • OR libsoftokn3-32bit-3.19.2_CKBI_1.98-0.10 is installed
  • OR mozilla-nspr-4.10.8-0.5 is installed
  • OR mozilla-nspr-32bit-4.10.8-0.5 is installed
  • OR mozilla-nss-3.19.2_CKBI_1.98-0.10 is installed
  • OR mozilla-nss-32bit-3.19.2_CKBI_1.98-0.10 is installed
  • OR mozilla-nss-tools-3.19.2_CKBI_1.98-0.10 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Desktop 12 is installed
  • AND Package Information
  • cron-4.2-55 is installed
  • OR cronie-1.4.11-55 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Desktop 12 SP1 is installed
  • AND Package Information
  • aaa_base-13.2+git20140911.61c1681-9 is installed
  • OR aaa_base-extras-13.2+git20140911.61c1681-9 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Desktop 12 SP2 is installed
  • AND bogofilter-1.2.4-5 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Desktop 12 SP3 is installed
  • AND fetchmail-6.3.26-12 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Desktop 12 SP4 is installed
  • AND Package Information
  • hplip-3.16.11-1 is installed
  • OR hplip-hpijs-3.16.11-1 is installed
  • OR hplip-sane-3.16.11-1 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for additional PackageHub packages 15 SP2 is installed
  • AND libjpeg-turbo-1.5.3-5.12 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for Desktop Applications 15 is installed
  • AND Package Information
  • cairo-1.15.10-4.5 is installed
  • OR libcairo2-32bit-1.15.10-4.5 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for Legacy Software 15 is installed
  • AND Package Information
  • java-1_8_0-openjdk-1.8.0.191-3.13 is installed
  • OR java-1_8_0-openjdk-demo-1.8.0.191-3.13 is installed
  • OR java-1_8_0-openjdk-devel-1.8.0.191-3.13 is installed
  • OR java-1_8_0-openjdk-headless-1.8.0.191-3.13 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for Live Patching 15 is installed
  • AND Package Information
  • kernel-default-4.12.14-25.19 is installed
  • OR kernel-default-livepatch-4.12.14-25.19 is installed
  • OR kernel-livepatch-4_12_14-25_19-default-1-1.3 is installed
  • OR kernel-livepatch-SLE15_Update_5-1-1.3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 SP2 is installed
  • AND Package Information
  • libX11-1.6.5-3.9 is installed
  • OR libX11-devel-32bit-1.6.5-3.9 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for Server Applications 15 is installed
  • AND Package Information
  • libmariadb-devel-3.1.2-3.9 is installed
  • OR libmariadb_plugins-3.1.2-3.9 is installed
  • OR libmysqld-devel-10.2.25-3.17 is installed
  • OR libmysqld19-10.2.25-3.17 is installed
  • OR mariadb-10.2.25-3.17 is installed
  • OR mariadb-client-10.2.25-3.17 is installed
  • OR mariadb-connector-c-3.1.2-3.9 is installed
  • OR mariadb-errormessages-10.2.25-3.17 is installed
  • OR mariadb-tools-10.2.25-3.17 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for Server Applications 15 SP1 is installed
  • AND Package Information
  • libecpg6-12.3-3.8 is installed
  • OR postgresql-12.0.1-8.14 is installed
  • OR postgresql-contrib-12.0.1-8.14 is installed
  • OR postgresql-devel-12.0.1-8.14 is installed
  • OR postgresql-docs-12.0.1-8.14 is installed
  • OR postgresql-plperl-12.0.1-8.14 is installed
  • OR postgresql-plpython-12.0.1-8.14 is installed
  • OR postgresql-pltcl-12.0.1-8.14 is installed
  • OR postgresql-server-12.0.1-8.14 is installed
  • OR postgresql-server-devel-12.0.1-8.14 is installed
  • OR postgresql12-12.3-3.8 is installed
  • OR postgresql12-contrib-12.3-3.8 is installed
  • OR postgresql12-devel-12.3-3.8 is installed
  • OR postgresql12-docs-12.3-3.8 is installed
  • OR postgresql12-plperl-12.3-3.8 is installed
  • OR postgresql12-plpython-12.3-3.8 is installed
  • OR postgresql12-pltcl-12.3-3.8 is installed
  • OR postgresql12-server-12.3-3.8 is installed
  • OR postgresql12-server-devel-12.3-3.8 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP1 is installed
  • AND Package Information
  • ImageMagick-6.8.8.1-30 is installed
  • OR libMagickCore-6_Q16-1-6.8.8.1-30 is installed
  • OR libMagickWand-6_Q16-1-6.8.8.1-30 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP1-LTSS is installed
  • AND Package Information
  • kgraft-patch-3_12_74-60_64_66-default-5-2 is installed
  • OR kgraft-patch-3_12_74-60_64_66-xen-5-2 is installed
  • OR kgraft-patch-SLE12-SP1_Update_23-5-2 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2 is installed
  • AND chrony-2.3-3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-BCL is installed
  • AND Package Information
  • git-2.12.3-27.14 is installed
  • OR git-core-2.12.3-27.14 is installed
  • OR git-doc-2.12.3-27.14 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-ESPOS is installed
  • AND Package Information
  • glibc-2.22-62.13 is installed
  • OR glibc-32bit-2.22-62.13 is installed
  • OR glibc-devel-2.22-62.13 is installed
  • OR glibc-devel-32bit-2.22-62.13 is installed
  • OR glibc-html-2.22-62.13 is installed
  • OR glibc-i18ndata-2.22-62.13 is installed
  • OR glibc-info-2.22-62.13 is installed
  • OR glibc-locale-2.22-62.13 is installed
  • OR glibc-locale-32bit-2.22-62.13 is installed
  • OR glibc-profile-2.22-62.13 is installed
  • OR glibc-profile-32bit-2.22-62.13 is installed
  • OR nscd-2.22-62.13 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-LTSS is installed
  • AND Package Information
  • kernel-firmware-20170530-21.22 is installed
  • OR ucode-amd-20170530-21.22 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3 is installed
  • AND clamav-0.99.2-32 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-ESPOS is installed
  • AND Package Information
  • libecpg6-10.9-1.12 is installed
  • OR libpq5-10.9-1.12 is installed
  • OR libpq5-32bit-10.9-1.12 is installed
  • OR postgresql10-10.9-1.12 is installed
  • OR postgresql10-contrib-10.9-1.12 is installed
  • OR postgresql10-docs-10.9-1.12 is installed
  • OR postgresql10-libs-10.9-1.12 is installed
  • OR postgresql10-plperl-10.9-1.12 is installed
  • OR postgresql10-plpython-10.9-1.12 is installed
  • OR postgresql10-pltcl-10.9-1.12 is installed
  • OR postgresql10-server-10.9-1.12 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-LTSS is installed
  • AND Package Information
  • glibc-2.22-62.22 is installed
  • OR glibc-32bit-2.22-62.22 is installed
  • OR glibc-devel-2.22-62.22 is installed
  • OR glibc-devel-32bit-2.22-62.22 is installed
  • OR glibc-html-2.22-62.22 is installed
  • OR glibc-i18ndata-2.22-62.22 is installed
  • OR glibc-info-2.22-62.22 is installed
  • OR glibc-locale-2.22-62.22 is installed
  • OR glibc-locale-32bit-2.22-62.22 is installed
  • OR glibc-profile-2.22-62.22 is installed
  • OR glibc-profile-32bit-2.22-62.22 is installed
  • OR nscd-2.22-62.22 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-TERADATA is installed
  • AND Package Information
  • gnome-shell-search-provider-nautilus-3.20.3-23.6 is installed
  • OR libnautilus-extension1-3.20.3-23.6 is installed
  • OR nautilus-3.20.3-23.6 is installed
  • OR nautilus-lang-3.20.3-23.6 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP4 is installed
  • AND Package Information
  • colord-gtk-lang-0.1.26-6 is installed
  • OR libcolord-gtk1-0.1.26-6 is installed
  • OR libcolord2-1.3.3-12 is installed
  • OR libcolord2-32bit-1.3.3-12 is installed
  • OR libcolorhug2-1.3.3-12 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 15-LTSS is installed
  • AND Package Information
  • libfreebl3-3.53-3.40 is installed
  • OR libfreebl3-32bit-3.53-3.40 is installed
  • OR libfreebl3-hmac-3.53-3.40 is installed
  • OR libfreebl3-hmac-32bit-3.53-3.40 is installed
  • OR libsoftokn3-3.53-3.40 is installed
  • OR libsoftokn3-32bit-3.53-3.40 is installed
  • OR libsoftokn3-hmac-3.53-3.40 is installed
  • OR libsoftokn3-hmac-32bit-3.53-3.40 is installed
  • OR mozilla-nspr-4.25-3.12 is installed
  • OR mozilla-nspr-32bit-4.25-3.12 is installed
  • OR mozilla-nspr-devel-4.25-3.12 is installed
  • OR mozilla-nss-3.53-3.40 is installed
  • OR mozilla-nss-32bit-3.53-3.40 is installed
  • OR mozilla-nss-certs-3.53-3.40 is installed
  • OR mozilla-nss-certs-32bit-3.53-3.40 is installed
  • OR mozilla-nss-devel-3.53-3.40 is installed
  • OR mozilla-nss-sysinit-3.53-3.40 is installed
  • OR mozilla-nss-tools-3.53-3.40 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Workstation Extension 15 is installed
  • AND Package Information
  • libntfs-3g87-2016.2.22-3.3 is installed
  • OR ntfs-3g-2016.2.22-3.3 is installed
  • OR ntfs-3g_ntfsprogs-2016.2.22-3.3 is installed
  • OR ntfsprogs-2016.2.22-3.3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Workstation Extension 15 SP2 is installed
  • AND transfig-3.2.6a-4.9 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud 6 is installed
  • AND mongodb-2.4.14-1 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud 7 is installed
  • AND Package Information
  • ansible-2.2.3.0-5 is installed
  • OR monasca-installer-20170912_10.45-5 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud 8 is installed
  • AND python-Twisted-15.2.1-9.8 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud Crowbar 8 is installed
  • AND python-PyKMIP-0.6.0-3.3 is installed
  • BACK